Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

https://www.securityweek.com/wp-content/uploads/2024/08/WordPress.jpeg

More than 200,000 WordPress websites are potentially exposed to takeover attacks via two critical-severity vulnerabilities in The Events Calendar plugin.

A highly popular plugin with over 600,000 active installations, The Events Calendar allows administrators to easily create and manage an events calendar on their websites.

All plugin versions before 6.17.3.1 are affected by two code injection bugs that could lead to remote code execution (RCE), allowing attackers to take over sites, WordPress security firm Defiant explains.

The first security defect, tracked as CVE-2026-78159 (CVSS score of 9.8), is described as an unauthenticated code injection caused by insufficient validation.

Under certain conditions, an attacker can inject a plain-array payload that bypasses checks and executes during the processing of single-event HTML, including the comment area.

StellarWP, The Events Calendar’s developer, patched the flaw on August 25 in version 6.17.3.1 of the plugin.

Advertisement. Scroll to continue reading.

Tracked as CVE-2026-78006 (CVSS...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more