TGViewer
Netlas.io Netlas.io @netlas · 2.31K subscribers
Post #632 346
CVE-2026-78006 & CVE-2026-78159: Two unauthenticated vulnerability chains leading to RCE in The Events Calendar Plugin for WordPress, 9.8 Rating 🔥

Two critical vulnerabilities were recently disclosed in The Events Calendar Plugin for WordPress. The first uses PHP Object Injection to execute arbitrary OS commands on the underlying server. The second allows an unauthenticated attacker to reset an administrator’s password, after which the attacker can upload a malicious plugin and take complete control of the site. The first vulnerability (CVE-2026-78006) is already being exploited in the wild!

Search at Netlas.io:
👉 Link: https://nt.ls/mEm8O
👉 Dork: http.body:"plugins/the-events-calendar"

Read more:
https://www.wordfence.com/blog/2026/09/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/
  • ❤ 1
  • 🔥 1
More from @netlas
  1. Sep 22, 2026CVE-2026-93952: Improper Input Validation in VeloCloud Orchestrator, 10.0 Rating 🔥 A rece…
  2. Sep 21, 2026CVE-2026-13684 and others: Multiple vulnerabilities in Synology DSM, up to 9.8 Rating 🔥 S…
  3. Sep 18, 202611 new vulnerabilities in WordPress, no CVE assigned yet ❗️ WordPress 7.1.1 security relea…
  4. Sep 17, 2026CVE-2026-20329 and others: Multiple vulnerabilities in Cisco ASA, up to 9.9 Rating 🔥 Cisc…
  5. Sep 16, 2026CVE-2026-61642: Request smuggling is possible in Squid proxy, 7.7 Rating 🔥 A recently dis…
  6. Sep 11, 2026🔌 Plug & Pwn: Mapping the Windows PnP Auto-Install Attack Surface Windows Plug & Play can…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →