CVE-2026-78159: The Events Calendar runs code through an unapproved comment
Published
The Events Calendar powers more than 600,000 WordPress sites. CVE-2026-78159, rated 9.8 out of 10, lets an unauthenticated attacker run code remotely. The chain goes through an unapproved comment carrying a `wp:legacy-widget` block and a PHP array, parsed by the `Element_Classes::parse_array()` function.
Fixed by the vendor: The Events Calendar 6.17.4.1 (10 September 2026; first fix 6.17.3.1 on 25 August)
What does this flaw actually do?
The plugin processes the content of some comments without checking the author’s identity. An unapproved comment can carry a `wp:legacy-widget` block holding a raw PHP array.
On render, `Element_Classes::parse_array()` parses that array and leads to remote code execution. No account, no moderator approval required: the worst case for such a widely deployed plugin.
Why are plugins your real attack surface?
An average WordPress site carries dozens of third-party plugins. Each has its own patch cadence and code quality; The Events Calendar, with over 600,000 installs, is a mass target.
Two flaws were disclosed together (CVE-2026-78159 and CVE-2026-78006), exposing more than 200,000 sites to full takeover. You control neither the vendor’s calendar nor the deployment delay across your clients.
How did the fix unfold?
StellarWP shipped a first fix on 25 August 2026 in version 6.17.3.1, then the complete fix in 6.17.4.1 on 10 September 2026.
Between discovery and actual deployment on each site, the exposure window stays the variable you control best - provided you filter upstream.
What should you do now?
Move The Events Calendar to 6.17.4.1 or later. Then audit the site’s files: a site exploited before the update may already host a webshell.
Filter unauthenticated comment requests carrying a `wp:legacy-widget` block and a PHP array at the edge: that is exactly what a virtual patch is for.
Who is affected?
- The Events Calendar for WordPress, versions ≤ 6.17.3
- CVSS: 9.8 (critical). Unauthenticated code execution through a comment
- Fixed in 6.17.4.1 (10 September 2026); first fix 6.17.3.1 on 25 August 2026
- Over 600,000 installs; more than 200,000 sites exposed to takeover
How does AtriShield stop it?
Virtual patch: the flaw is neutralised at the entrance of your server, without changing your application and without waiting for a maintenance window. Decisions and logs stay inside your infrastructure.
- ✓Virtual patch on the comments endpoint: unauthenticated requests carrying a `wp:legacy-widget` block and a PHP array are cut before WordPress.
- ✓Coverage extends to third-party plugins, not just WordPress core.
- ✓No change to your theme, your plugins or your host; nothing to redeploy.
- ✓The vendor fix still has to be applied: the virtual patch covers the gap, it does not replace it.
Sources
- SecurityWeek - Unauthenticated RCE flaws could expose 200,000+ WordPress sites to takeover
- SC Media - Flaws in The Events Calendar WordPress plugin enable unauthenticated RCE
Analysis published by Atrilya Solutions, based on public security reporting. The links above point to the original sources.