Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Major Vulnerabilities Found in WordPress Plugin

Major Vulnerabilities Found in WordPress Plugin

Posted on September 15, 2026 By CWS

Two significant security flaws have been identified in the popular WordPress plugin, The Events Calendar, posing a serious threat to over 600,000 websites. Discovered by Wordfence Argus, the vulnerabilities allow unauthorized individuals to potentially seize control of affected websites.

Details of the Security Flaws

The vulnerabilities could enable remote code execution, reset admin passwords, spread malware, and even lead to a complete server compromise. These issues were found in the widget-rendering process of the plugin, making them exploitable without needing user authentication or interaction.

The Events Calendar, managed by StellarWP, has been impacted by these security threats. Site administrators are urged to update to version 6.17.4.1 or later to safeguard their systems.

Exploring the First Vulnerability

Identified as CVE-2026-78006, this vulnerability has a critical CVSS score of 9.8. It affects versions up to 6.17.4 and exploits a PHP object injection flaw. Attackers can execute system commands on the server by submitting malicious comments on event pages, particularly when comments are enabled.

This attack takes advantage of the way The Events Calendar processes comments as Gutenberg blocks. If a specially crafted serialized PHP payload is submitted, it can bypass standard validation, leading to unauthorized command execution and potential data breaches.

The Second Vulnerability Explained

The second flaw, CVE-2026-78159, also with a CVSS score of 9.8, affects versions up to 6.17.3. This issue utilizes a different approach, passing a crafted array through the plugin’s safety checks to execute unauthorized actions.

Attackers can manipulate this flaw to reset administrator passwords and gain control of the site. Once inside, they could upload malicious plugins, enabling remote code execution and further compromising the security of the website.

StellarWP was informed of these vulnerabilities on August 24, 2026, and quickly released patches. Wordfence Premium users received protection measures on August 22, while free users are scheduled to get updates by September 21, 2026.

The Path Forward for Site Owners

Owners of sites using The Events Calendar should immediately update to the latest version, disable comments on event pages if unnecessary, and scrutinize plugins and administrator accounts for any irregular activity. Ensuring these measures will help protect against potential security breaches.

For those interested in enhancing their security strategies, exploring AI SOC deployment phases could provide valuable insights into protecting digital assets.

Cyber Security News Tags:CVE-2026-78006, CVE-2026-78159, plugin vulnerabilities, remote code execution, StellarWP, The Events Calendar, website security, website takeover, Wordfence, WordPress

Post navigation

Previous Post: Microsoft Sets AI Cybersecurity Boundaries in New Code
Next Post: Apple Fixes Over 200 Bugs in iOS 27, macOS Golden Gate

Related Posts

CISA Alerts on GitLab Vulnerability Exploitation CISA Alerts on GitLab Vulnerability Exploitation Cyber Security News
Microsoft Probes Leak in Early Alert System as Chinese Hackers Exploit SharePoint Vulnerabilities Microsoft Probes Leak in Early Alert System as Chinese Hackers Exploit SharePoint Vulnerabilities Cyber Security News
Microsoft Enhances Windows 11 with March 2026 Updates Microsoft Enhances Windows 11 with March 2026 Updates Cyber Security News
Top 10 Best Security Orchestration, Automation, And Response (SOAR) Tools in 2025 Top 10 Best Security Orchestration, Automation, And Response (SOAR) Tools in 2025 Cyber Security News
Critical Vulnerability In Chromium’s Blink Let Attackers Crash Chromium-based Browsers Within Seconds Critical Vulnerability In Chromium’s Blink Let Attackers Crash Chromium-based Browsers Within Seconds Cyber Security News
PagerDuty Confirms Data Breach After Third-Party App Vulnerability Exposes Salesforce Data PagerDuty Confirms Data Breach After Third-Party App Vulnerability Exposes Salesforce Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Target Gitea RCE Flaw to Hijack Servers
  • Apple Fixes Over 200 Bugs in iOS 27, macOS Golden Gate
  • Major Vulnerabilities Found in WordPress Plugin
  • Microsoft Sets AI Cybersecurity Boundaries in New Code
  • Leading Kubernetes Security Tools for 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Target Gitea RCE Flaw to Hijack Servers
  • Apple Fixes Over 200 Bugs in iOS 27, macOS Golden Gate
  • Major Vulnerabilities Found in WordPress Plugin
  • Microsoft Sets AI Cybersecurity Boundaries in New Code
  • Leading Kubernetes Security Tools for 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark