CVE-2026-78006 & CVE-2026-78159: Two unauthenticated vulnerability chains leading to RCE in The Events Calendar Plugin for WordPress, 9.8 Rating 🔥
Two critical vulnerabilities were recently disclosed in The Events Calendar Plugin for WordPress. The first uses PHP Object Injection to execute arbitrary OS commands on the underlying server. The second allows an unauthenticated attacker to reset an administrator’s password, after which the attacker can upload a malicious plugin and take complete control of the site. The first vulnerability (CVE-2026-78006) is already being exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/mEm8O
👉 Dork: http.body:"plugins/the-events-calendar"
Read more:
https://www.wordfence.com/blog/2026/09/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/
Post #632
346

- ❤ 1
- 🔥 1