CRITICAL
9.8 CVE-2026-78006 Published 12 Sept 2026
WordPress The Events Calendar RCE Bug
Worried this affects one of your servers?
The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution (RCE) in versions up to 6.17.4.
An insufficient protection in the is_safe_widget_instance function can be bypassed, allowing unauthenticated attackers to execute code on the server.
This vulnerability is exploitable without authentication or approval, requiring only that comments are enabled and visible on events.
Reference: CVE-2026-78006 on NVD
← Back to Security News