DIRAS TAKE
Urgent: public exploit code exists and no fixed release is recorded, so prioritize mitigating internet-facing sites running The Events Calendar. Immediately reduce exposure and apply the vendor's guidance where available.
What is CVE-2026-78006?
Unauthenticated attackers can execute arbitrary code on servers running The Events Calendar; this is tracked as CVE-2026-78006. The flaw affects 6.x releases up through 6.17.4 and earlier, and does not require a logged-in account. Exploitation requires that comments are enabled and visible on event pages so an attacker can deliver crafted content that reaches the vulnerable unserialize path; public exploit code for the issue has been published and no vendor fix is listed in the affected metadata. The weakness is classified as CWE-502 (Deserialization of Untrusted Data).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of stellarwp The Events Calendar are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 6.x | 6.17.4 and earlier |
Is CVE-2026-78006 being exploited?
Public exploit code is available.
How to fix CVE-2026-78006
- Disable or restrict comments on event pages to prevent the unauthenticated submission vector.
- Restrict public access to event pages with comments or block the plugin's endpoints via web server or WAF rules.
- Monitor web and application logs for signs of malicious serialized payloads or unusual POST requests to comment endpoints.
- Apply any vendor guidance or updates from StellarWP as soon as a fixed version is released.
Frequently asked questions
Is CVE-2026-78006 being actively exploited?
Public exploit code is available for The Events Calendar vulnerability; there is no CISA KEV listing noted in the provided facts.
Which The Events Calendar versions are affected by CVE-2026-78006?
The Events Calendar 6.x releases up through 6.17.4 and earlier are listed as affected.
Is there a patch for CVE-2026-78006?
No fixed version is indicated in the affected metadata; a vendor patch is not listed in the provided facts.
Does CVE-2026-78006 require authentication?
No authentication is required for the vulnerability, but exploitation requires that comments be enabled and visible on event pages.
References
- nvd.nist.gov/vuln/detail/CVE-2026-78006
- cve.org/CVERecord?id=CVE-2026-78006
- wordfence.com/threat-intel/vulnerabilities/id/a0c67346-534a-4b67-a904-fa148703707a?source=cve
- plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Template_Bootstrap.php#L213
- plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Widgets/Service_Provider.php#L295
- plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Widgets/Service_Provider.php#L255
- plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Collections/Lazy_Post_Collection.php#L82
- plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/common/src/Tribe/Utils/Collection_Trait.php#L247
- plugins.trac.wordpress.org/changeset?reponame=&old=3690576%40the-events-calendar&new=3690576%40the-events-calendar
- All stellarwp CVEs on CVE Radar
- CVEs published in September 2026