The Events Calendar Had Two Critical RCE Flaws. Here's What to Check
Wordfence disclosed two separate, independent critical vulnerabilities in The Events Calendar plugin on August 21 and 22, 2026, both scoring 9.8 out of 10 on severity, and both exploitable without any login at all. If you or a client runs event listings on WordPress, this plugin is extremely likely to be the one behind it. The Events Calendar has over 600,000 active installs, and I would check your version today.
What actually happened, and why two separate bugs matter
These are not two symptoms of the same root cause. They are two genuinely different ways into the same plugin, found close together but through different code paths.
The first, CVE-2026-78006, starts with something ordinary looking, a comment on an event page. If a site has comments enabled on events and a specific "show comments" setting turned on, an attacker can submit a specially crafted comment that triggers PHP object injection through a flawed deserialization routine. From there, an attacker can run operating system commands directly on the server, with whatever permissions the web server itself has.
The second, CVE-2026-78159, does not touch comments at all. It exploits the plugin's widget rendering system with a carefully shaped array that slips past the plugin's own safety check. That data then reaches a part of the code that accepts callable PHP functions, which an attacker can abuse to trigger dangerous WordPress functions and, ultimately, remote code execution.
Both were found by Wordfence Argus, Wordfence's AI-assisted vulnerability research system, within a single day of each other. I think that detail is worth sitting with for a second. Two independent, unauthenticated, critical-severity paths into the same widely used plugin, discovered back to back. That is not a sign the plugin is uniquely careless. It is a sign that automated vulnerability research is starting to find things at a pace manual auditing did not previously match.
Who is actually affected
The first issue affects The Events Calendar up to version 6.17.4. The second affects versions up to 6.17.3. Update to version 6.17.4.1 or later to close both. The comment-based attack path specifically requires comments to be enabled on event pages with the "Show comments on event pages" setting active, so if that setting is off, your exposure to that particular chain is narrower, though I would not treat that as a reason to skip updating, since the second chain does not depend on comments at all.
How to check if you were already hit
Both attack paths lead toward the same broad outcome, an attacker running arbitrary code with your web server's permissions. That opens the door to data theft, site defacement, malware planted on the server, or using your site as a foothold to reach other things on the same hosting environment. Look for anything you cannot account for. Unexpected files in your uploads directory, an admin or editor account you do not recognize, or changes to core files and plugins you did not make. If you use a security plugin that logs file changes or admin activity, review that log around late August for anything unusual.
The catch: this is part of a genuinely busy month for WordPress security
I do not want to leave the impression this is an isolated event, because it is not. In the weeks around this disclosure, security researchers also published a critical unauthenticated remote code execution chain in WordPress core itself, not a plugin, affecting default installs of WordPress 6.9.0 through 7.0.1, patched in 6.9.5 and 7.0.2. Separately, five more critical plugin and theme vulnerabilities landed in the same stretch, including flaws in the Avada theme, the WPMU DEV Dashboard plugin, and GiveWP, the last one scoring a perfect 10.0.
If you manage several WordPress sites, I would treat late August into September 2026 as a stretch worth a full audit pass, not just a single plugin update. Check your WordPress core version specifically, since the core vulnerability requires no plugins at all to be exploitable, which makes it the more dangerous of the two stories here if your core version has not been touched recently.
What I would actually do this week
Update The Events Calendar to 6.17.4.1 or later first, since that closes both disclosed chains. Then check your WordPress core version and confirm it is at least 6.9.5 or 7.0.2, whichever branch you are on. If you manage client sites, I would run this same two-step check across every site on your list today, not on your normal update schedule, given how much unauthenticated, no-interaction-required severity landed in this window at once.
FAQ
Do I need both vulnerabilities to be exploited together, or is either one enough on its own?
Either one alone is enough to compromise a site. They are independent attack paths, not a chain that requires both to work.
Does disabling comments on event pages fully protect me?
No. That only closes the first attack path. The second, through the widget rendering system, does not depend on comments being enabled at all, so updating the plugin is the only complete fix.
Is the free version of The Events Calendar affected, or only a paid add-on?
This affects The Events Calendar plugin itself, the core event management plugin from StellarWP, not a separate paid add-on.
How would I know if Wordfence Argus, the AI tool that found this, flagged anything on my own site?
Wordfence Argus is a research tool used to find new vulnerabilities in plugin code generally, not a scanner that runs against your specific live site. Protecting your own site still comes down to updating promptly and checking for signs of compromise, the same as with any other disclosed vulnerability.
Should I be more worried about the WordPress core RCE chain or this plugin issue?
I would treat the core vulnerability as the higher priority to confirm you are patched against, purely because it requires no plugins and no special configuration at all. That said, if you actually run The Events Calendar, this issue is just as directly exploitable and equally worth fixing today.
Bottom line
Update The Events Calendar to 6.17.4.1 or later today if you have not already, and use this as the prompt to also confirm your WordPress core version is current, since a separate, unrelated core vulnerability landed in the same narrow window. Two unauthenticated, critical severity issues in one widely used plugin, found a day apart, is exactly the kind of thing worth checking across every site you manage, not just the one you remember has events on it.
Sources: Cyber Security News, Critical WordPress Plugin Flaws Put Over 600,000 Websites at Risk of Takeover, citing Wordfence research; wp2shell technical writeup, CVE-2026-63030 and CVE-2026-60137. Verified against reported disclosure details on September 21, 2026.
Comments 0
Be the first to comment.
Leave a comment