The Events Calendar WordPress Plugin Vulnerable to Remote Code Execution
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- the events calendar (wordpress)
- Patched version
- Not yet available
The Events Calendar plugin for WordPress is under investigation for a critical vulnerability that could allow Remote Code Execution. Users of versions up to 6.17.3 are advised to take immediate action.
What happened
An early warning has been issued regarding a critical vulnerability in The Events Calendar plugin for WordPress. This vulnerability, tracked as CVE-2026-78159, affects all versions up to and including 6.17.3. The flaw lies in the parse_array function, which could enable unauthenticated attackers to execute code on the server.
The vulnerability was first flagged on September 12, 2026. Although there are no reports of this vulnerability being exploited in the wild, the potential impact is severe due to the possibility of Remote Code Execution. Users are urged to assess their exposure by checking their plugin versions and reviewing comments on tribe_events posts for any suspicious activity.
What to do about it
- Upgrade The Events Calendar plugin to a version beyond 6.17.3.
- Review comments on tribe_events posts for any suspicious activity.
- Monitor the NVD for updates on CVE-2026-78006 and CVE-2026-78159.
- Consider implementing additional security measures to protect your WordPress site from potential attacks.
How 0Day would have caught this
the events calendar is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using The Events Calendar plugin version 6.17.3 or earlier, you are potentially affected.
What should I do right now?
Immediately upgrade The Events Calendar plugin to a version beyond 6.17.3 and review comments on tribe_events posts for any suspicious activity.
Is there an official fix available?
No official fix has been published yet. Monitor the NVD for updates on CVE-2026-78006 and CVE-2026-78159.