Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

High · 7.0 WordPress CVE-2026-78006 CVE-2026-78159

The Events Calendar WordPress Plugin: Two Unauthenticated RCE Vulnerabilities (CVE-2026-78006, CVE-2026-78159)

Two critical unauthenticated remote code execution vulnerabilities (CVSS 9.8) affect The Events Calendar WordPress plugin. Both rely on crafted comments combined with insecure deserialization paths. No fixed version has been confirmed yet.

Synthesized by AI from 4 sources · updated 1 hour ago

AI summary

The Events Calendar, a widely used WordPress plugin for managing events, is affected by two separate critical vulnerabilities that each allow unauthenticated remote code execution. Both issues share a similar attack pattern involving the plugin's handling of comments on single-event pages and insecure object/widget deserialization logic. The vulnerabilities are tracked as CVE-2026-78006 and CVE-2026-78159.

What Happened

Two critical remote code execution vulnerabilities were disclosed in The Events Calendar WordPress plugin. CVE-2026-78006 affects versions up to and including 6.17.4, and CVE-2026-78159 affects versions up to and including 6.17.3. Both received a CVSS score of 9.8 (Critical) and allow unauthenticated attackers to execute arbitrary code on the server.

Technical Cause

CVE-2026-78006 (CWE-502, Deserialization of Untrusted Data) stems from insufficient protection in the plugin's is_safe_widget_instance function. PHP's behavior of firing magic methods during pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute, allows the protection to be bypassed before unserialize() is reached. CVE-2026-78159 (CWE-94, Code Injection) is caused by insufficient validation of the widget 'classes' map in the parse_array function. A plain-array payload can bypass the is_safe_widget_instance() object check and reach a callable-invocation sink inside Element_Classes::parse_array(). In both cases, the plugin's V2 single-event template runs do_blocks() over buffered comment HTML. For CVE-2026-78006, WordPress returns a moderation-hash URL that lets an unauthenticated commenter immediately view their own pending comment, delivering injected block markup to the vulnerable code path before moderation occurs. For CVE-2026-78159, the attack is triggered when do_blocks() processes single-event HTML that includes a submitted comment containing a crafted wp:legacy-widget block.

Why It Matters

Both vulnerabilities allow full server-side code execution without requiring authentication, administrative approval, or any user interaction beyond submitting a comment. Given the popularity of The Events Calendar plugin, the potential impact of these flaws is significant for sites that have comments enabled on event pages.

Who Is Affected

Sites running The Events Calendar plugin with comments enabled and visible on events are affected. For CVE-2026-78006, exploitation requires that comments are enabled and visible on events. For CVE-2026-78159, exploitation requires that comments are enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted.

Affected Versions

CVE-2026-78006 affects The Events Calendar versions up to and including 6.17.4, with a fix referenced at 6.17.4.1. CVE-2026-78159 affects versions up to and including 6.17.3, with a fix referenced at 6.17.3.1. The fact package does not confirm that a fixed version has actually been released; the fixed version numbers referenced in the source data represent the version boundary at which the vulnerability no longer applies, but the package explicitly marks fix_available as false for both CVEs.

Fixes and Mitigation

The fact package indicates that no fix is currently confirmed to be available for either vulnerability (fix_available: false), despite version boundaries of 6.17.4.1 and 6.17.3.1 being referenced in the affected-range data. This is a discrepancy in the source data that should be treated with caution. Site administrators should verify directly with the plugin vendor or the WordPress plugin repository whether an update addressing these issues has been released.

Recommended Action

Until a confirmed fix is verified, site administrators using The Events Calendar should consider disabling comments on event pages as a mitigation, since both vulnerabilities depend on comment submission to deliver the malicious payload. Administrators should monitor the plugin's official changelog and the WordPress.org plugin repository for an update and apply it as soon as it is confirmed available.

PatchBriefing score

7.0 / 10 · High

Official CVSS: 9.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Why this score

Both vulnerabilities received a patchwire_score of 7, driven primarily by their CVSS base score of 9.8 (Critical), reflecting unauthenticated, network-exploitable code execution with no required user interaction and high impact to confidentiality, integrity, and availability. Additional contributing factors include the unauthenticated remote attack vector, lack of required user interaction, the current absence of a confirmed fix, and the plugin's large install base (approximately 600,000 sites). No evidence of known exploitation in the wild or public exploit code was found in the fact package, and no EPSS score was available.

Affected versions

The Events Calendar < 6.17.4.1
vulnerable
The Events Calendar < 6.17.3.1
vulnerable

Reported fixes

The fact package indicates that no fix is currently confirmed to be available for either vulnerability (fix_available: false), despite version boundaries of 6.17.4.1 and 6.17.3.1 being referenced in the affected-range data. This is a discrepancy in the source data that should be treated with caution. Site administrators should verify directly with the plugin vendor or the WordPress plugin repository whether an update addressing these issues has been released.

How this was built

4 source records were collected, matched and used to prepare the report above.

  • WPVulnerability database
  • NVD (NIST) database
  • WPVulnerability database
  • NVD (NIST) database
Unified report
The Events Calendar WordPress Plugin: Two Unauthenticated RCE Vulnerabilities (CVE-2026-78006, CVE-2026-78159)
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email