CVE-2026-78159
The Events Calendar plugin for WordPress is vulnerable to remote code execution in all versions up to and including 6.17.3. An attacker can inject malicious code by submitting a specially crafted comment that contains a wp:legacy-widget block, which is processed when the event page is rendered. This flaw allows unauthenticated attackers to run arbitrary code on the server.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
The Events Calendar plugin for WordPress, versions up to and including 6.17.3, on sites that have comments enabled for tribe_events posts.
Real-world impact
An attacker could execute arbitrary code on the server, potentially taking full control of the site, exfiltrating data, or installing malware.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is remotely exploitable without authentication, has a high impact on confidentiality, integrity, and availability, and requires minimal effort to exploit.
What to do about it
- ›Disable comments on tribe_events posts to prevent the exploit chain.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
NVD description
Timeline
How it’s attacked
References & advisories
- plugins.trac.wordpress.org/browser/the-events-calendar…
- plugins.trac.wordpress.org/browser/the-events-calendar…
- plugins.trac.wordpress.org/browser/the-events-calendar…
- plugins.trac.wordpress.org/browser/the-events-calendar…
- plugins.trac.wordpress.org/changeset
- plugins.trac.wordpress.org/changeset
- wordfence.com/threat-intel/vulnerabilitie…