chiprook
← Security
SecuritySeptember 16, 2026, 18:32

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites

Two critical vulnerabilities (CVE-2026-78159 and CVE-2026-78006, CVSS 9.8) were found in the WordPress plugin The Events Calendar, allowing unauthenticated code execution and site takeover. Developer StellarWP fixed them in versions 6.17.3.1 and 6.17.4.1; about 240,000 sites are vulnerable.

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites
#WordPress#TheEventsCalendar#StellarWP
Read next
Security

Google Releases AndroidX Libraries for Granular Android Patch Checks

Security

Surfshark: iPhone lets you delete 98% of preinstalled apps, Google only 38%

Security

Hackers extract 1.6 million images and 27,000 videos from a single Flock camera

Security

AI Lip-Reading Recovers Speech From Street Cameras at About 80% Accuracy