CVE Tools
Back to feed
Patch released The Events Calendar plugin web-app WordPress rce

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

StellarWP has patched two unauthenticated remote code execution flaws in The Events Calendar plugin for WordPress: CVE-2026-78159 and CVE-2026-78006, both rated CVSS 9.8. The bugs can allow code or PHP object injection and could result in a complete WordPress site takeover when event comments are enabled. Administrators should update to The Events Calendar 6.17.4.1, as versions before 6.17.3.1 are exposed to both issues and CVE-2026-78006 is fixed in 6.17.4.1.