DIRAS TAKE
Urgent: unauthenticated RCE with public exploit code available — immediately reduce exposure by disabling or restricting the comment/widget attack surface and monitor for exploit activity.
What is CVE-2026-78159?
An attacker with no login can execute code on a site running The Events Calendar plugin; this is CVE-2026-78159. The issue affects versions through 6.17.3. A flaw in how the plugin parses widget class data lets a specially crafted array bypass safety checks and reach a callable execution path. Successful exploitation requires comments to be enabled on tribe_events posts and at least one comment containing a malicious wp:legacy-widget block that is later rendered by do_blocks.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of stellarwp The Events Calendar are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 6.x | 6.17.3 and earlier |
Is CVE-2026-78159 being exploited?
Public exploit code is available.
How to fix CVE-2026-78159
- Disable or restrict comments on tribe_events posts until a vendor fix is published.
- Block or sanitize wp:legacy-widget blocks in incoming comments using filters or a WAF rule.
- Follow and apply vendor guidance when a patch is released and review logs for suspicious do_blocks/widget processing.
Frequently asked questions
Is CVE-2026-78159 being actively exploited?
Public exploit code is available for CVE-2026-78159, which increases the risk of active exploitation.
Which The Events Calendar versions are affected by CVE-2026-78159?
All The Events Calendar versions up to and including 6.17.3 are affected.
Is there a patch for CVE-2026-78159?
No fixed version is listed in the provided facts; await vendor-provided updates and apply them when available.
Does CVE-2026-78159 require authentication?
No; the vulnerability can be triggered by unauthenticated actors if comments are enabled on tribe_events and a crafted comment exists.
References
- nvd.nist.gov/vuln/detail/CVE-2026-78159
- cve.org/CVERecord?id=CVE-2026-78159
- wordfence.com/threat-intel/vulnerabilities/id/cc2ccfeb-6df6-4fee-96a5-94f8dd131f7c?source=cve
- plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/common/src/Tribe/Utils/Element_Classes.php#L211
- plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/views/v2/components/messages.php#L30
- plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Widgets/Service_Provider.php#L279
- plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Template_Bootstrap.php#L214
- plugins.trac.wordpress.org/changeset?reponame=&old=3667866%40the-events-calendar&new=3667866%40the-events-calendar
- plugins.trac.wordpress.org/changeset?reponame=&old=3667867%40the-events-calendar&new=3667867%40the-events-calendar
- All stellarwp CVEs on CVE Radar
- CVEs published in September 2026