WP Vulnerability WatchVulnerability data as of September 12, 2026

Vulnerability alerts / September 11, 2026

Vulnerability in The Events Calendar — CVE-2026-78159

CriticalSeverity
CVSS 9.8
Estimated exploit probability
EPSS
600,000+ sitesInstalls
6.17.3.1Fixed in

What to do now

Update The Events Calendar to 6.17.3.1 or later.

Affected versions

  • Everything up to and including 6.17.3

Affected: The Events Calendar (plugin, the-events-calendar)

Check: The plugin on wordpress.org / Our record for The Events Calendar

What the vulnerability is

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the targeted site has comments enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted, as the attack chain is triggered when do_blocks() processes the single-event HTML including the comment area.

This description is reproduced verbatim from the public vulnerability record.

Sources

Part of this record comes from Wordfence Intelligence. Original: https://www.wordfence.com/threat-intel/vulnerabilities/id/cc2ccfeb-6df6-4fee-96a5-94f8dd131f7c
Copyright 2012-2026 Defiant Inc. / Full license text

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts