Vulnerability
Published 2026-09-16
Verified 2026-09-19

The Events Calendar (WordPress): two unauth RCE chains (CVE-2026-78159, CVE-2026-78006); CVSS 9.8

Wordfence/Defiant (wired by SecurityWeek 16 September 2026) documents two critical unauthenticated remote-code-execution chains in StellarWP The Events Calendar plugin (~600k+ installs; ~240k on vulnerable branches per SW). CVE-2026-78159 (CVSS 9.8): unauthenticated code injection via insufficient validation when processing single-event HTML/comment area — patched in 6.17.3.1 (25 August 2026). CVE-2026-78006 (CVSS 9.8): unauthenticated PHP object injection when event comments are enabled/visible — payload reaches the vulnerable path before moderation; patched in 6.17.4.1 (10 September 2026). Both can fully compromise the WordPress site. Update to 6.17.4.1 or later. Primary research: Wordfence Argus blog (URL may be bot-gated); wire: SecurityWeek.

Product
The Events Calendar (WordPress plugin; StellarWP)
Versions
Prior to 6.17.3.1 (CVE-2026-78159); prior to 6.17.4.1 (CVE-2026-78006)
CVSS
9.8
Exploited in Australia?
unknown
Patch to
6.17.4.1 or later

Primary: Wordfence — The Events Calendar unauth RCE chains · Vendor: StellarWP / The Events Calendar · CVE: CVE-2026-78159, CVE-2026-78006 · SecurityWeek — Events Calendar RCE (16 Sep 2026)

vulnerabilities cloud