• PoC PUBLIC

CVE-2026-78159: pre-auth remote code execution in stellarwp The Events Calendar

An attacker with no login can execute code on a site running The Events Calendar plugin; this is CVE-2026-78159. The issue affects versions through 6.17.3. A flaw in how the plugin parses widget class data lets a specially crafted array bypass safety checks and reach a callable execution path. Successful exploitation requires comments to be enabled on tribe_events posts and at least one comment containing a malicious wp:legacy-widget block that is later rendered by do_blocks.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.01394
CWE
CWE-94
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: unauthenticated RCE with public exploit code available — immediately reduce exposure by disabling or restricting the comment/widget attack surface and monitor for exploit activity.

What is CVE-2026-78159?

An attacker with no login can execute code on a site running The Events Calendar plugin; this is CVE-2026-78159. The issue affects versions through 6.17.3. A flaw in how the plugin parses widget class data lets a specially crafted array bypass safety checks and reach a callable execution path. Successful exploitation requires comments to be enabled on tribe_events posts and at least one comment containing a malicious wp:legacy-widget block that is later rendered by do_blocks.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of stellarwp The Events Calendar are affected?

BRANCHAFFECTEDFIXED
6.x6.17.3 and earlier

Is CVE-2026-78159 being exploited?

Public exploit code is available.

How to fix CVE-2026-78159

  1. Disable or restrict comments on tribe_events posts until a vendor fix is published.
  2. Block or sanitize wp:legacy-widget blocks in incoming comments using filters or a WAF rule.
  3. Follow and apply vendor guidance when a patch is released and review logs for suspicious do_blocks/widget processing.

Frequently asked questions

Is CVE-2026-78159 being actively exploited?

Public exploit code is available for CVE-2026-78159, which increases the risk of active exploitation.

Which The Events Calendar versions are affected by CVE-2026-78159?

All The Events Calendar versions up to and including 6.17.3 are affected.

Is there a patch for CVE-2026-78159?

No fixed version is listed in the provided facts; await vendor-provided updates and apply them when available.

Does CVE-2026-78159 require authentication?

No; the vulnerability can be triggered by unauthenticated actors if comments are enabled on tribe_events and a crafted comment exists.

References