Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover
Two critical unauthenticated remote code execution (RCE) vulnerabilities affect The Events Calendar WordPress plugin versions before 6.17.3.1 and 6.17.4.1. These flaws allow attackers to execute arbitrary code and potentially take over affected WordPress sites. The first vulnerability (CVE-2026-78159) involves unauthenticated code injection via insufficient validation, patched in version 6.17.3.1. The second (CVE-2026-78006) is an unauthenticated PHP object injection exploitable if event comments are enabled, fixed in version 6.17.4.1. Approximately 240,000 sites using vulnerable versions may be exposed, though exploitation requires comments to be enabled. Both vulnerabilities lead to full site compromise if exploited.
AI Analysis
Technical Summary
The Events Calendar WordPress plugin contains two independent critical-severity vulnerabilities enabling unauthenticated remote code execution. CVE-2026-78159 is an unauthenticated code injection due to insufficient input validation, allowing attackers to inject payloads processed in event HTML rendering. CVE-2026-78006 is an unauthenticated PHP object injection flaw exploitable via event comments before moderation. Both vulnerabilities allow attackers to execute arbitrary code and fully compromise affected WordPress installations. The first was patched in version 6.17.3.1 and the second in 6.17.4.1. Approximately 240,000 WordPress sites using versions prior to 6.17 are potentially vulnerable, with exploitation of the second requiring comments to be enabled and visible.
Potential Impact
Successful exploitation of either vulnerability results in remote code execution, enabling attackers to take complete control over affected WordPress sites running The Events Calendar plugin. This can lead to site takeover, data compromise, and further malicious activities. The vulnerabilities are unauthenticated, increasing risk as no credentials are required. However, the second vulnerability requires comments to be enabled on events. The widespread use of the plugin (over 600,000 active installations) means a large number of sites are potentially at risk.
Mitigation Recommendations
Both vulnerabilities have been officially patched by the vendor StellarWP. Users should upgrade The Events Calendar plugin to version 6.17.4.1 or later to remediate both issues. Specifically, version 6.17.3.1 fixes CVE-2026-78159 and version 6.17.4.1 fixes CVE-2026-78006. Sites unable to immediately update should consider disabling comments on events as a temporary mitigation for CVE-2026-78006. Patch status is confirmed by the vendor advisory.
Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover
Description
Two critical unauthenticated remote code execution (RCE) vulnerabilities affect The Events Calendar WordPress plugin versions before 6.17.3.1 and 6.17.4.1. These flaws allow attackers to execute arbitrary code and potentially take over affected WordPress sites. The first vulnerability (CVE-2026-78159) involves unauthenticated code injection via insufficient validation, patched in version 6.17.3.1. The second (CVE-2026-78006) is an unauthenticated PHP object injection exploitable if event comments are enabled, fixed in version 6.17.4.1. Approximately 240,000 sites using vulnerable versions may be exposed, though exploitation requires comments to be enabled. Both vulnerabilities lead to full site compromise if exploited.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Events Calendar WordPress plugin contains two independent critical-severity vulnerabilities enabling unauthenticated remote code execution. CVE-2026-78159 is an unauthenticated code injection due to insufficient input validation, allowing attackers to inject payloads processed in event HTML rendering. CVE-2026-78006 is an unauthenticated PHP object injection flaw exploitable via event comments before moderation. Both vulnerabilities allow attackers to execute arbitrary code and fully compromise affected WordPress installations. The first was patched in version 6.17.3.1 and the second in 6.17.4.1. Approximately 240,000 WordPress sites using versions prior to 6.17 are potentially vulnerable, with exploitation of the second requiring comments to be enabled and visible.
Potential Impact
Successful exploitation of either vulnerability results in remote code execution, enabling attackers to take complete control over affected WordPress sites running The Events Calendar plugin. This can lead to site takeover, data compromise, and further malicious activities. The vulnerabilities are unauthenticated, increasing risk as no credentials are required. However, the second vulnerability requires comments to be enabled on events. The widespread use of the plugin (over 600,000 active installations) means a large number of sites are potentially at risk.
Mitigation Recommendations
Both vulnerabilities have been officially patched by the vendor StellarWP. Users should upgrade The Events Calendar plugin to version 6.17.4.1 or later to remediate both issues. Specifically, version 6.17.3.1 fixes CVE-2026-78159 and version 6.17.4.1 fixes CVE-2026-78006. Sites unable to immediately update should consider disabling comments on events as a temporary mitigation for CVE-2026-78006. Patch status is confirmed by the vendor advisory.
Technical Details
- Classification
- {"confidence":0.83,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/unauthenticated-rce-flaws-could-expose-200000-wordpress-sites-to-takeover/","fetched":true,"fetchedAt":"2026-09-16T11:46:36.158Z","wordCount":1002}
Threat ID: 6aaa819c55bf5e2cf58bf784
Added to database: 09/16/2026, 11:46:36 UTC
Last enriched: 09/16/2026, 11:46:42 UTC
Last updated: 09/17/2026, 04:58:16 UTC
Views: 38
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.