Alert

Alert 2026-102 Critical Vulnerabilities in The Events Calendar plugin for WordPress

Affected product(s):

ProductCVEAffected versionsFixed version
The Events Calendar for WordPressCVE‑2026‑78159Up to 6.17.3, inclusive6.17.3.1 or later
The Events Calendar for WordPressCVE‑2026‑78006Up to 6.17.4, inclusive6.17.4.1 or later
The Events Calendar for WordPressBoth vulnerabilitiesVersions prior to 6.17.4.16.17.4.1 or later

*Version 6.17.4.1, released on September 10, 2026, is the first release that contains fixes for both vulnerabilities.

Description

Two critical remote code execution (RCE) vulnerabilities were identified in the The Events Calendar plugin for WordPress, developed by StellarWP. The flaws, CVE‑2026‑78006 and CVE‑2026‑78159, have a CVSS 9.8 score and allow remote unauthenticated attackers to take control of vulnerable sites under certain conditions, without requiring registration, login, or victim interaction.

The plugin has more than 600,000 active installations. StellarWP published fixes for both vulnerability chains; it is recommended to update immediately to The Events Calendar 6.17.4.1 or a later version and perform a review for possible compromise, especially if the site allows comments on individual event pages.

The vulnerabilities are located in the widget rendering process of The Events Calendar, particularly when the plugin processes content from an individual event page, including comments pending moderation. The attacker does not need the comment to be approved: WordPress allows whoever published a comment to view their own pending comment through a moderation link, which can cause attacker-controlled content to reach the vulnerable plugin logic.

CVECVSSTypeMain conditionImpact
CVE‑2026‑780069.8 — CriticalPHP Object InjectionComments enabled on event pages and “Show comments on event pages” option activeExecution of system commands and RCE with permissions of the web server user
CVE‑2026‑781599.8 — CriticalCode injection via callable invocation / insufficient validationProcessing of controlled content within event widgetsAdministrative password reset, admin access, and subsequent RCE

Solution

The definitive solution is to update The Events Calendar to version 6.17.4.1 or later:

Since it is a critical RCE, easy to exploit, it is recommended after updating to follow the following verification steps:

  1. Purge WordPress, PHP, CDN, and WAF caches to ensure the updated code is loaded.
  2. Confirm that comments are not enabled on event pages if that functionality is not required.
  3. Review administrative accounts, plugins, files, and logs to rule out prior exploitation.
  4. If signs of compromise are identified, isolate the site, preserve evidence, restore from a trusted backup, and rotate credentials for WordPress, hosting, database, SFTP/SSH, APIs, and integrated services.

Additional information: