Critical RCE Flaws in The Events Calendar Plugin Put 200,000+ WordPress Sites at Risk
Two critical unauthenticated vulnerabilities (CVE-2026-78006 and CVE-2026-78159), each scoring 9.8 on the CVSS scale, have been identified in The Events Calendar WordPress plugin by Wordfence Argus. The flaws allow anonymous attackers to achieve remote code execution by posting a crafted comment on an event page and previewing it via a moderation-hash URL, without requiring login or admin approval. The first attack chain exploits unsafe PHP deserialization to execute OS commands directly on the web server, while the second uses an extract()-based code path to change the administrator password, enabling malicious plugin installation. Both chains are triggered because the plugin incorrectly processes unapproved comments as Gutenberg blocks, passing attacker-controlled data through insufficient security checks. No exploitation in the wild has been reported so far, but sites with comments enabled on public event pages are considered at immediate risk.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in