• PoC PUBLIC

CVE-2026-78006: pre-auth remote code execution in stellarwp The Events Calendar

Unauthenticated attackers can execute arbitrary code on servers running The Events Calendar; this is tracked as CVE-2026-78006. The flaw affects 6.x releases up through 6.17.4 and earlier, and does not require a logged-in account. Exploitation requires that comments are enabled and visible on event pages so an attacker can deliver crafted content that reaches the vulnerable unserialize path; public exploit code for the issue has been published and no vendor fix is listed in the affected metadata.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.0147
CWE
CWE-502
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code exists and no fixed release is recorded, so prioritize mitigating internet-facing sites running The Events Calendar. Immediately reduce exposure and apply the vendor's guidance where available.

What is CVE-2026-78006?

Unauthenticated attackers can execute arbitrary code on servers running The Events Calendar; this is tracked as CVE-2026-78006. The flaw affects 6.x releases up through 6.17.4 and earlier, and does not require a logged-in account. Exploitation requires that comments are enabled and visible on event pages so an attacker can deliver crafted content that reaches the vulnerable unserialize path; public exploit code for the issue has been published and no vendor fix is listed in the affected metadata. The weakness is classified as CWE-502 (Deserialization of Untrusted Data).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of stellarwp The Events Calendar are affected?

BRANCHAFFECTEDFIXED
6.x6.17.4 and earlier

Is CVE-2026-78006 being exploited?

Public exploit code is available.

How to fix CVE-2026-78006

  1. Disable or restrict comments on event pages to prevent the unauthenticated submission vector.
  2. Restrict public access to event pages with comments or block the plugin's endpoints via web server or WAF rules.
  3. Monitor web and application logs for signs of malicious serialized payloads or unusual POST requests to comment endpoints.
  4. Apply any vendor guidance or updates from StellarWP as soon as a fixed version is released.

Frequently asked questions

Is CVE-2026-78006 being actively exploited?

Public exploit code is available for The Events Calendar vulnerability; there is no CISA KEV listing noted in the provided facts.

Which The Events Calendar versions are affected by CVE-2026-78006?

The Events Calendar 6.x releases up through 6.17.4 and earlier are listed as affected.

Is there a patch for CVE-2026-78006?

No fixed version is indicated in the affected metadata; a vendor patch is not listed in the provided facts.

Does CVE-2026-78006 require authentication?

No authentication is required for the vulnerability, but exploitation requires that comments be enabled and visible on event pages.

References