VENDOR

stellarwp vulnerabilities: CVEs, exploitation and patches

Every stellarwp CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-78006
    The Events Calendar pre-auth remote code execution via widget unserialize stellarwp The Events Calendar ·
    • PoC PUBLIC
    CRITICAL 9.8
  2. CVE-2026-78159
    The Events Calendar remote code execution via widget parsing stellarwp The Events Calendar ·
    • PoC PUBLIC
    CRITICAL 9.8
2 CVEs · page 1 of 1