Two critical unauthenticated vulnerabilities in StellarWP's The Events Calendar WordPress plugin—CVE-2026-78006 and CVE-2026-78159, both rated CVSS 9.8—can enable takeover of more than 600,000 active sites. The flaws abuse attacker-controlled comment content processed as Gutenberg blocks and the plugin's generation of integrity hashes for legacy-widget instances. CVE-2026-78006 permits PHP object injection and arbitrary operating-system command execution, while CVE-2026-78159 can invoke arbitrary PHP callables; researchers demonstrated an administrator-password reset that can lead to site compromise and remote code execution.
Exploitation requires comments to be enabled and displayed on event posts, but requires no account, registration, or moderator approval: attackers can abuse the pending-comment moderation-preview flow. StellarWP addressed CVE-2026-78159 in version 6.17.3.1 and both vulnerabilities in 6.17.4.1. Administrators should update immediately, review event-post comment configurations, investigate administrator accounts for unauthorized changes, and examine logs for suspicious comment or moderation-preview activity.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
StellarWP released a fully patched update addressing the arbitrary-callable issue; the fully patched The Events Calendar release is version 6.17.4.1. The two chains, tracked as CVE-2026-78006 and CVE-2026-78159, could respectively enable OS command execution or administrator account takeover without authentication when event comments are enabled and shown.
StellarWP released a patch for the first-disclosed vulnerability in The Events Calendar.
StellarWP acknowledged both reports submitted through the Wordfence Vulnerability Management Portal.
Wordfence Argus discovered the second critical vulnerability chain in The Events Calendar plugin.
Wordfence Premium, Care, and Response customers received firewall protection for known exploit attempts targeting the vulnerabilities.
Wordfence Argus discovered the first of two critical unauthenticated vulnerability chains affecting StellarWP's The Events Calendar plugin.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.