Skip to content
Writing
By MD Jehad H.··4 min read·Operator playbook

This WordPress plugin vulnerability needs a same-day fix

Drafted through my n8n + AI pipeline, edited by me.

The Events Calendar, a WordPress plugin installed on more than 600,000 small business sites, has two critical vulnerabilities under active exploitation this week, and both can be closed with one update.

Wordfence disclosed the two-vulnerability chain on September 14, 2026. Both are rated 9.8 out of 10 on the CVSS scale, and neither requires a login, an account, or admin approval to exploit. StellarWP shipped the fix in version 6.17.4.1 on September 10, four days before the public disclosure, so a patch already exists. The gap now is how many sites have actually installed it.

What this WordPress plugin vulnerability actually does

The first bug, CVE-2026-78006, uses PHP object injection to run operating system commands on the server through a crafted event comment. The second, CVE-2026-78159, abuses an arbitrary-callable function to reset the site administrator's password. Chained together, an attacker with no account at all can end up with full control of the WordPress install, including the ability to upload their own plugin and take the site over completely.

Who's exposed right now

  • Running The Events Calendar or Events Calendar Pro below version 6.17.4.1
  • Comments on events are turned on and visible to the public
  • No web application firewall rule covering this CVE pair
  • Nobody has checked the plugin version since before September 10

Attack chain showing how a crafted event comment leads to full WordPress site takeover through The Events Calendar plugin

  1. 01Trigger

    Attacker submits a crafted event comment

    no login needed

  2. 02Action

    Object injection runs arbitrary code

    CVE-2026-78006, CVSS 9.8

  3. 03Action

    Admin password reset is abused

    CVE-2026-78159

  4. 04Alert

    Malicious plugin is uploaded

    full site takeover

Wordfence blocked 1,113 attempts against this chain in a single 24-hour window this week.

What to do today

  1. 1

    Confirm your version

    Open Plugins in your WordPress dashboard and check The Events Calendar version. Anything before 6.17.4.1 is exposed.

  2. 2

    Update immediately

    Update to 6.17.4.1 or later. If auto-updates are off for this plugin, turn them on while you're already in there.

  3. 3

    Check for new admin accounts

    Look under Users for any administrator account you don't recognize, especially ones created in the last week.

  4. 4

    Turn off event comments if you don't need them

    The object injection path requires comments to be enabled and visible on events. Turning them off closes one entry point even before you patch.

  5. 5

    Ask whoever manages your site to confirm in writing

    If a host or agency manages your WordPress install, don't assume they've already handled this. Send them the CVE numbers and ask for written confirmation.

If you don't recognize this plugin by name

The Events Calendar shows up on plenty of sites that use it only for a location page or store hours, not just event businesses. If your site has any kind of calendar or events page and you didn't build it yourself, check the plugin list before assuming this doesn't apply to you.

If you're not sure whether your site, or a client's site, is exposed, or you want a second set of eyes on your WordPress maintenance routine in general, bring me what you're running and we'll go through it together.

Building something this should run inside?

Book a systems call

Keep reading