Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites
Two critical vulnerabilities (CVE-2026-78159 and CVE-2026-78006, CVSS 9.8) were found in the WordPress plugin The Events Calendar, allowing unauthenticated code execution and site takeover. Developer StellarWP fixed them in versions 6.17.3.1 and 6.17.4.1; about 240,000 sites are vulnerable.
- CVE-2026-78159: unauthenticated code injection, fixed August 25 in 6.17.3.1
- CVE-2026-78006: PHP object injection, fixed September 10 in 6.17.4.1
- Both flaws rated CVSS 9.8 and lead to full site takeover
- About 240,000 sites run plugin versions before 6.17
Read next
Security