CVE-2026-78006
Last modified
CVE-2026-78006 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached.
Description
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached. This makes it possible for unauthenticated attackers to execute code on the server. This is exploitable without authentication or approval because the plugin's V2 single-event template runs do_blocks() over buffered comment HTML, and WordPress returns a moderation-hash URL that allows an unauthenticated commenter to immediately view their own pending comment, delivering the injected block markup to the vulnerable code path before any moderation occurs. This does require comments to be enabled and visible on events.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| stellarwp | The Events Calendar | <= 6.17.4 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-78006?
How severe is CVE-2026-78006?
How do I fix CVE-2026-78006?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-77997Joomla Extension - yootheme.com - Authenticated, privileged …5.1
- CVE-2026-77998Joomla Extension - miniorange.com - Unauthenticated Authenti…10
- CVE-2026-77999Joomla Extension - j2commerce.com - Unauthenticated PayPal c…8.7
- CVE-2026-78000Joomla Extension - j2commerce.com - Reflected XSS via `filte…5.3
- CVE-2026-78002A flaw was found in rsyslog. An unauthenticated remote attac…7.5
- CVE-2026-78003The Mailgun for WordPress plugin for WordPress is vulnerable…9.8
- CVE-2026-78008A buffer overflow vulnerability in the WatchGuard Fireware O…8.6
- CVE-2026-78009An out-of-bounds read vulnerability in the WatchGuard Firewa…8.7
- CVE-2026-78010A stack-based buffer overflow vulnerability in the WatchGuar…8.7
- CVE-2026-78011An integer underflow vulnerability in the WatchGuard Firewar…8.7
- CVE-2026-78012An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 co…9.8
- CVE-2026-7802The Frontend Admin by DynamiApps plugin for WordPress is vul…8.8
Are you affected by CVE-2026-78006?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
