This WordPress plugin vulnerability needs a same-day fix
Drafted through my n8n + AI pipeline, edited by me.
The Events Calendar, a WordPress plugin installed on more than 600,000 small business sites, has two critical vulnerabilities under active exploitation this week, and both can be closed with one update.
Wordfence disclosed the two-vulnerability chain on September 14, 2026. Both are rated 9.8 out of 10 on the CVSS scale, and neither requires a login, an account, or admin approval to exploit. StellarWP shipped the fix in version 6.17.4.1 on September 10, four days before the public disclosure, so a patch already exists. The gap now is how many sites have actually installed it.
What this WordPress plugin vulnerability actually does
The first bug, CVE-2026-78006, uses PHP object injection to run operating system commands on the server through a crafted event comment. The second, CVE-2026-78159, abuses an arbitrary-callable function to reset the site administrator's password. Chained together, an attacker with no account at all can end up with full control of the WordPress install, including the ability to upload their own plugin and take the site over completely.
Who's exposed right now
- Running The Events Calendar or Events Calendar Pro below version 6.17.4.1
- Comments on events are turned on and visible to the public
- No web application firewall rule covering this CVE pair
- Nobody has checked the plugin version since before September 10
Attack chain showing how a crafted event comment leads to full WordPress site takeover through The Events Calendar plugin
- 01Trigger
Attacker submits a crafted event comment
no login needed
- 02Action
Object injection runs arbitrary code
CVE-2026-78006, CVSS 9.8
- 03Action
Admin password reset is abused
CVE-2026-78159
- 04Alert
Malicious plugin is uploaded
full site takeover
What to do today
- 1
Confirm your version
Open Plugins in your WordPress dashboard and check The Events Calendar version. Anything before 6.17.4.1 is exposed.
- 2
Update immediately
Update to 6.17.4.1 or later. If auto-updates are off for this plugin, turn them on while you're already in there.
- 3
Check for new admin accounts
Look under Users for any administrator account you don't recognize, especially ones created in the last week.
- 4
Turn off event comments if you don't need them
The object injection path requires comments to be enabled and visible on events. Turning them off closes one entry point even before you patch.
- 5
Ask whoever manages your site to confirm in writing
If a host or agency manages your WordPress install, don't assume they've already handled this. Send them the CVE numbers and ask for written confirmation.
If you don't recognize this plugin by name
The Events Calendar shows up on plenty of sites that use it only for a location page or store hours, not just event businesses. If your site has any kind of calendar or events page and you didn't build it yourself, check the plugin list before assuming this doesn't apply to you.
If you're not sure whether your site, or a client's site, is exposed, or you want a second set of eyes on your WordPress maintenance routine in general, bring me what you're running and we'll go through it together.
Building something this should run inside?
Book a systems callKeep reading
wordpress
The WooCommerce plugin vulnerability worth checking today
A critical WooCommerce plugin vulnerability is under active attack, and the fix takes about twenty minutes once you know where to look.
wordpress
WordPress security updates just got more urgent
WordPress security updates are shipping faster after an AI-driven report spike, and a monthly check is no longer a safe patch cadence.
wordpress
The abilities API lets AI run your WordPress
WordPress 7.1 shipped an abilities API that lets AI agents create posts and update inventory on your site. Here is what to expose and what to lock down.