CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-78006 — The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut...

·Source: NIST NVD

Updated:

Executive Summary

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attri

Analysis

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached. This makes it possible for unauthenticated attackers to execute code on the server. This is exploitable without authentication or approval because the plugin's V2 single-event template runs do_blocks() over buffered comment HTML, and WordPress returns a moderation-hash URL that allows an unauthenticated commenter to immediately view their own pending comment, delivering the injected block markup to the vulnerable code path before any moderation occurs. This does require comments to be enabled and visible on events. CVSS Score: 9.8. Published: 2026-09-12T08:16:24.240.

Indicators of Compromise (1)

CVE (1)
CVE-2026-78006
Source Attribution

Originally published by NIST NVD on Sep 12, 2026. Verified by: NIST.

Related Threats

MEDIUMVulnerability

When the Whole Company Adopts AI: What It Does to Your SOC

Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and non-technical staff signing consumer AI tools into corporate

The Hacker News
CRITICALVulnerability

NVD CRITICAL: CVE-2026-78159 — The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut...

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it p

CVE-2026-78159
NIST NVD
MEDIUMVulnerability

Cylake Gets $245M to Build Cloud-Free Cybersecurity Platform

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/cylake-gets-245m-to-build-cloud-free-cybersecurity-platform-image_small-1-a-32807.jpg" align=right hspace=4><b>Nir Zuk's Startup Targets Firms Unable to Send Sensitive Security Data to the Cloud</b><br>Cylake, led by Palo Alto Networks founder Nir Zuk, raised $245 million to build an on-premises cybersecurity system combining hard

Bank Info Security