Two significant security flaws have been identified in the popular WordPress plugin, The Events Calendar, posing a serious threat to over 600,000 websites. Discovered by Wordfence Argus, the vulnerabilities allow unauthorized individuals to potentially seize control of affected websites.
Details of the Security Flaws
The vulnerabilities could enable remote code execution, reset admin passwords, spread malware, and even lead to a complete server compromise. These issues were found in the widget-rendering process of the plugin, making them exploitable without needing user authentication or interaction.
The Events Calendar, managed by StellarWP, has been impacted by these security threats. Site administrators are urged to update to version 6.17.4.1 or later to safeguard their systems.
Exploring the First Vulnerability
Identified as CVE-2026-78006, this vulnerability has a critical CVSS score of 9.8. It affects versions up to 6.17.4 and exploits a PHP object injection flaw. Attackers can execute system commands on the server by submitting malicious comments on event pages, particularly when comments are enabled.
This attack takes advantage of the way The Events Calendar processes comments as Gutenberg blocks. If a specially crafted serialized PHP payload is submitted, it can bypass standard validation, leading to unauthorized command execution and potential data breaches.
The Second Vulnerability Explained
The second flaw, CVE-2026-78159, also with a CVSS score of 9.8, affects versions up to 6.17.3. This issue utilizes a different approach, passing a crafted array through the plugin’s safety checks to execute unauthorized actions.
Attackers can manipulate this flaw to reset administrator passwords and gain control of the site. Once inside, they could upload malicious plugins, enabling remote code execution and further compromising the security of the website.
StellarWP was informed of these vulnerabilities on August 24, 2026, and quickly released patches. Wordfence Premium users received protection measures on August 22, while free users are scheduled to get updates by September 21, 2026.
The Path Forward for Site Owners
Owners of sites using The Events Calendar should immediately update to the latest version, disable comments on event pages if unnecessary, and scrutinize plugins and administrator accounts for any irregular activity. Ensuring these measures will help protect against potential security breaches.
For those interested in enhancing their security strategies, exploring AI SOC deployment phases could provide valuable insights into protecting digital assets.
