CRITICAL
9.8 CVE-2026-78159 Published 12 Sept 2026
WordPress The Events Calendar RCE Flaw
Worried this affects one of your servers?
The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution (RCE) in versions up to 6.17.3.
This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array().
Exploitation requires that the targeted site has comments enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted.
Reference: CVE-2026-78159 on NVD
← Back to Security News