High · 7.0 WordPress CVE-2026-78006 CVE-2026-78159
The Events Calendar WordPress Plugin: Two Unauthenticated RCE Vulnerabilities (CVE-2026-78006, CVE-2026-78159)
Two critical unauthenticated remote code execution vulnerabilities (CVSS 9.8) affect The Events Calendar WordPress plugin. Both rely on crafted comments combined with insecure deserialization paths. No fixed version has been confirmed yet.
AI summary
The Events Calendar, a widely used WordPress plugin for managing events, is affected by two separate critical vulnerabilities that each allow unauthenticated remote code execution. Both issues share a similar attack pattern involving the plugin's handling of comments on single-event pages and insecure object/widget deserialization logic. The vulnerabilities are tracked as CVE-2026-78006 and CVE-2026-78159.
What Happened
Two critical remote code execution vulnerabilities were disclosed in The Events Calendar WordPress plugin. CVE-2026-78006 affects versions up to and including 6.17.4, and CVE-2026-78159 affects versions up to and including 6.17.3. Both received a CVSS score of 9.8 (Critical) and allow unauthenticated attackers to execute arbitrary code on the server.
Technical Cause
CVE-2026-78006 (CWE-502, Deserialization of Untrusted Data) stems from insufficient protection in the plugin's is_safe_widget_instance function. PHP's behavior of firing magic methods during pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute, allows the protection to be bypassed before unserialize() is reached. CVE-2026-78159 (CWE-94, Code Injection) is caused by insufficient validation of the widget 'classes' map in the parse_array function. A plain-array payload can bypass the is_safe_widget_instance() object check and reach a callable-invocation sink inside Element_Classes::parse_array(). In both cases, the plugin's V2 single-event template runs do_blocks() over buffered comment HTML. For CVE-2026-78006, WordPress returns a moderation-hash URL that lets an unauthenticated commenter immediately view their own pending comment, delivering injected block markup to the vulnerable code path before moderation occurs. For CVE-2026-78159, the attack is triggered when do_blocks() processes single-event HTML that includes a submitted comment containing a crafted wp:legacy-widget block.
Why It Matters
Both vulnerabilities allow full server-side code execution without requiring authentication, administrative approval, or any user interaction beyond submitting a comment. Given the popularity of The Events Calendar plugin, the potential impact of these flaws is significant for sites that have comments enabled on event pages.
Who Is Affected
Sites running The Events Calendar plugin with comments enabled and visible on events are affected. For CVE-2026-78006, exploitation requires that comments are enabled and visible on events. For CVE-2026-78159, exploitation requires that comments are enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted.
Affected Versions
CVE-2026-78006 affects The Events Calendar versions up to and including 6.17.4, with a fix referenced at 6.17.4.1. CVE-2026-78159 affects versions up to and including 6.17.3, with a fix referenced at 6.17.3.1. The fact package does not confirm that a fixed version has actually been released; the fixed version numbers referenced in the source data represent the version boundary at which the vulnerability no longer applies, but the package explicitly marks fix_available as false for both CVEs.
Fixes and Mitigation
The fact package indicates that no fix is currently confirmed to be available for either vulnerability (fix_available: false), despite version boundaries of 6.17.4.1 and 6.17.3.1 being referenced in the affected-range data. This is a discrepancy in the source data that should be treated with caution. Site administrators should verify directly with the plugin vendor or the WordPress plugin repository whether an update addressing these issues has been released.
Recommended Action
Until a confirmed fix is verified, site administrators using The Events Calendar should consider disabling comments on event pages as a mitigation, since both vulnerabilities depend on comment submission to deliver the malicious payload. Administrators should monitor the plugin's official changelog and the WordPress.org plugin repository for an update and apply it as soon as it is confirmed available.
PatchBriefing score
7.0 / 10 · High
Official CVSS: 9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Why this score
Both vulnerabilities received a patchwire_score of 7, driven primarily by their CVSS base score of 9.8 (Critical), reflecting unauthenticated, network-exploitable code execution with no required user interaction and high impact to confidentiality, integrity, and availability. Additional contributing factors include the unauthenticated remote attack vector, lack of required user interaction, the current absence of a confirmed fix, and the plugin's large install base (approximately 600,000 sites). No evidence of known exploitation in the wild or public exploit code was found in the fact package, and no EPSS score was available.
Affected versions
- The Events Calendar < 6.17.4.1
- vulnerable
- The Events Calendar < 6.17.3.1
- vulnerable
Reported fixes
The fact package indicates that no fix is currently confirmed to be available for either vulnerability (fix_available: false), despite version boundaries of 6.17.4.1 and 6.17.3.1 being referenced in the affected-range data. This is a discrepancy in the source data that should be treated with caution. Site administrators should verify directly with the plugin vendor or the WordPress plugin repository whether an update addressing these issues has been released.
How this was built
4 source records were collected, matched and used to prepare the report above.
-
WPVulnerability database
-
NVD (NIST) database
-
WPVulnerability database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email