Over 200,000 WordPress websites face potential security threats due to critical vulnerabilities in The Events Calendar plugin, a widely used tool with more than 600,000 active installations. These flaws could allow attackers to take control of affected sites, as reported by WordPress security company Defiant.
Understanding the Vulnerabilities
The Events Calendar plugin is susceptible to two significant vulnerabilities affecting all versions prior to 6.17.3.1. These issues involve code injection bugs that can lead to remote code execution (RCE), effectively allowing unauthorized access to the site.
The first vulnerability, CVE-2026-78159, has been assigned a CVSS score of 9.8, indicating its critical nature. It involves an unauthenticated code injection resulting from insufficient validation, enabling attackers to introduce payloads that bypass security checks during the processing of single-event HTML content.
Patch Implementations by StellarWP
In response to these threats, StellarWP, the developer behind The Events Calendar, released a patch on August 25 in version 6.17.3.1 to address CVE-2026-78159. This update aims to fortify the plugin against unauthorized code injection attempts.
The second vulnerability, CVE-2026-78006, also with a CVSS score of 9.8, arises from an unauthenticated PHP object injection issue. This flaw can be exploited when comments on events are enabled, as the injected code is processed by a vulnerable function before moderation, allowing attackers to execute malicious commands.
Widespread Impact and Update Urgency
StellarWP addressed the second vulnerability with the release of version 6.17.4.1 on September 10. Despite these patches, many WordPress sites remain at risk, with data indicating approximately 240,000 installations of versions prior to 6.17 still in use.
From September 10 to 14, the plugin was downloaded over 300,000 times, suggesting that a significant number of installations may remain unprotected against CVE-2026-78006. The actual number of vulnerable sites is uncertain, as exploitation hinges on the activation of comments within the plugin.
Website administrators are urged to update The Events Calendar plugin immediately to mitigate these security risks and protect their WordPress sites from potential takeovers.
