More than 200,000 WordPress websites may be exposed to takeover attacks through two critical-severity vulnerabilities in The Events Calendar plugin. StellarWP has released patches for CVE-2026-78159 and CVE-2026-78006, both of which can lead to remote code execution and full site compromise. #TheEventsCalendar #StellarWP #CVE-2026-78159 #CVE-2026-78006
Keypoints
- The Events Calendar plugin has over 600,000 active installations.
- Versions before 6.17.3.1 are affected by two critical code injection flaws.
- CVE-2026-78159 can allow unauthenticated code injection and remote code execution.
- CVE-2026-78006 is an unauthenticated PHP object injection issue tied to event comments.
- Both vulnerabilities can lead to full WordPress site compromise if comments are enabled.