Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover
More than 200,000 WordPress websites may be exposed to takeover attacks through two critical-severity vulnerabilities in The Events Calendar plugin. StellarWP has released patches for CVE-2026-78159 and CVE-2026-78006, both of which can lead to remote code execution and full site compromise. #TheEventsCalendar #StellarWP #CVE-2026-78159 #CVE-2026-78006

Keypoints

  • The Events Calendar plugin has over 600,000 active installations.
  • Versions before 6.17.3.1 are affected by two critical code injection flaws.
  • CVE-2026-78159 can allow unauthenticated code injection and remote code execution.
  • CVE-2026-78006 is an unauthenticated PHP object injection issue tied to event comments.
  • Both vulnerabilities can lead to full WordPress site compromise if comments are enabled.

Read More: https://www.securityweek.com/unauthenticated-rce-flaws-could-expose-200000-wordpress-sites-to-takeover/