CVE-2026-78159 carries a CVSS 3.1 base score of 9.8 against The Events Calendar, a WordPress event-listing plugin published by StellarWP. NVD classifies it as CWE-94 (Improper Control of Generation of Code) and describes an unauthenticated remote-code-execution path affecting releases up to and including 6.17.3. VulnCheck’s KEV feed reports the CVE as exploited, dated September 14, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-78159 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description locates the defect in Element_Classes::parse_array(): the plugin validates a widget’s classes map by checking that it is an object, but a plain-array payload bypasses that is_safe_widget_instance() object check and reaches a callable-invocation sink inside parse_array() — meaning attacker-supplied data ends up invoked as executable code rather than treated as inert configuration.
The exploitation precondition matches CVE-2026-78006, published against the same plugin within the same second in NVD’s timestamps: the targeted site must have comments enabled on tribe_events posts, and at least one comment carrying a crafted wp:legacy-widget block must already be present, because the attack chain fires when do_blocks() processes the single-event page’s HTML — including its comment area. A site with comments disabled or hidden on event posts is not reachable through this specific path.
Two bypasses of the same gate
is_safe_widget_instance() is meant to be the single checkpoint that decides whether a widget instance is safe to process further. CVE-2026-78006 defeats it through PHP’s pre-parse magic-method behavior combined with a forged wp_hash integrity attribute; this CVE defeats it by handing the gate a plain array instead of the object type it checks for. Two different techniques, one shared target, disclosed and patched on the same day — which is a stronger signal that a security researcher (or StellarWP’s own review) systematically probed that single checkpoint’s assumptions than that these are coincidentally unrelated findings.
The practical consequence: patching the version that fixes one bypass does not by itself confirm the other is fixed. Confirm the installed version resolves both CVE-2026-78159 and CVE-2026-78006 against StellarWP’s own changelog, not against a single CVE’s advisory in isolation.
Evidence and confidence
- Medium confidence — the CVSS 9.8 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-94 classification, theparse_array()mechanism, and the 6.17.3 affected-version ceiling all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone. - Unknown — exploitation probability. FIRST’s EPSS model scores this CVE 0.00762, 53.6th percentile as of our ingestion — a middling figure that does not itself indicate active mass exploitation.
No field is in conflict between our two sources. As with its companion CVE, our data carries no structured fixed-version field; NVD names 6.17.3 only as the affected ceiling.
Why this matters
The shared precondition across both Events Calendar CVEs — comments enabled and visible on event posts — is a real limiting factor, not a footnote to dismiss. Sites running The Events Calendar purely as an internal or authenticated-only calendar with comments closed are not exposed by either path. Sites that allow public comment on events, which is a common configuration for community organizations, ticketed venues, and conference sites soliciting attendee questions, face unauthenticated RCE from either bug independently.
NVD’s own description states the outcome as unauthenticated code execution, which is sufficient grounds to patch regardless of KEV status. The VulnCheck listing is a real, if single-sourced, indication that at least one of these two mechanisms has been observed in the wild.
Frequently Asked Questions
What is CVE-2026-78159? A CVSS 9.8 code-injection vulnerability (CWE-94) in The Events Calendar, a WordPress plugin from StellarWP, that NVD states allows unauthenticated remote code execution in versions through 6.17.3.
Is CVE-2026-78159 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 14, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration. Treat it as reported exploitation, not confirmed.
What has to be true for my site to be exposed?
Comments must be enabled and visible on your site’s event posts, and an attacker needs to have submitted at least one comment containing a crafted wp:legacy-widget block. Sites with comments disabled on events are not reachable through this specific path.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
How does this relate to CVE-2026-78006?
Both bypass the same is_safe_widget_instance() safety check in The Events Calendar, disclosed and patched the same day. CVE-2026-78006 exploits PHP’s pre-parse magic-method firing plus a forged integrity hash; this one exploits an object-type check that a plain array can bypass. Confirm your update resolves both, not just one.
Severity, vector, weakness classification, mechanism, and affected-version ceiling sourced from the National Vulnerability Database record for CVE-2026-78159. Exploitation status and the September 14, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.