Skip to main content
QUIETLYTIC
Vulnerability

The Events Calendar Insecure Deserialization (CVE-2026-78006)

CVE-2026-78006 is a CVSS 9.8 deserialization flaw enabling unauthenticated RCE in WordPress plugin The Events Calendar, reported exploited by VulnCheck KEV.

CVE-2026-78006
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
The Events Calendar, StellarWP The Events Calendar (through 6.17.4)

CVE-2026-78006 carries a CVSS 3.1 base score of 9.8 against The Events Calendar, a WordPress event-listing plugin published by StellarWP. NVD classifies it as CWE-502 (Deserialization of Untrusted Data) and describes an unauthenticated remote-code-execution path affecting releases up to and including 6.17.4. VulnCheck’s KEV feed reports the CVE as exploited, dated September 12, 2026.

That exploitation report is single-sourced — say so up front rather than in a footnote. CISA has not added CVE-2026-78006 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog is deliberately broader than CISA’s, admitting vendor and researcher exploitation reporting that CISA’s own listing criteria haven’t (yet) accepted. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing — that directive is triggered by CISA KEV inclusion, not by exploitation as such.

What the flaw is

NVD’s description names the specific defect: the plugin’s is_safe_widget_instance() function is meant to gate which widget instances are safe to unserialize, but PHP fires magic methods during the pre-parse stage of unserialize(), before that gate can act. A helper function, enable_rendering_widget_copied(), compounds the problem by forging a valid wp_hash integrity attribute on attacker-controlled data before it reaches unserialize() — so the integrity check that would normally block a tampered payload instead validates one deliberately crafted to pass it.

NVD also documents how an unauthenticated visitor reaches that code path at all: the plugin’s V2 single-event template runs do_blocks() over buffered comment HTML, and WordPress exposes a moderation-hash URL that lets an unauthenticated commenter view their own pending comment immediately — delivering attacker-supplied block markup to the vulnerable rendering path before any moderator has approved it. The precondition NVD states explicitly: comments must be enabled and visible on the site’s event posts. A site that has disabled or hidden comments on events is not exposed by this specific path, whatever else its comment configuration allows elsewhere.

Evidence and confidence

  • Medium confidence — the CVSS 9.8 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-502 classification, the mechanism (is_safe_widget_instance() bypass via PHP’s pre-parse magic-method firing plus a forged wp_hash), and the 6.17.4 affected-version ceiling all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone.
  • Unknown — exploitation probability. FIRST’s EPSS model puts this CVE at a 0.00778 score, 54th percentile as of our ingestion — middling relative to the broader EPSS population, not itself evidence of active mass exploitation.

No field is in conflict between the two sources we hold. One gap worth stating plainly: our data carries no structured fixed-version field, and NVD’s description names 6.17.4 only as the affected ceiling — it does not confirm which later release remediates the issue.

A companion bypass shipped the same day

NVD’s published_at timestamp for this record and for CVE-2026-78159 — a second unauthenticated RCE in the same plugin, via a different bypass of the same is_safe_widget_instance() gate — fall within the same second, September 12, 2026 at 08:16:24 UTC, roughly 137 milliseconds apart. These are not two independent discoveries; they are two distinct ways of defeating the same protective function, disclosed and patched together. VulnCheck’s KEV catalog lists them on different dates (this one September 12, the other September 14), which is a detail of when each entry was added to that catalog, not evidence they were found or fixed separately. A site patching one without checking whether it also needs the other’s fix is not fully remediated.

The Events Calendar’s parent company, StellarWP, also publishes GiveWP, the WordPress donation plugin behind CVE-2026-82222 — a separate CVSS 10.0 deserialization flaw disclosed in August 2026. The two products share a vendor, not a codebase defect; nothing in our evidence ties the underlying bugs together beyond that.

Why this matters

Unauthenticated RCE via deserialization is a severe outcome, but the precondition here — comments enabled and visible on event posts — narrows the exposed population in a way a bare CVSS score does not communicate. A site that has closed comments site-wide, or specifically on its events post type, is not reachable through this path regardless of plugin version. A site that has left comments open on events, which is a common default for community and ticketing sites that want attendee discussion, is fully exposed to an unauthenticated attacker.

The severity case for patching promptly does not need VulnCheck’s exploitation report to carry it: NVD’s own description states unauthenticated RCE as the outcome, which is sufficient grounds to upgrade regardless of catalog status. The KEV listing adds urgency and is a real, if uncorroborated, signal that this specific mechanism has moved from theoretical to observed.

Frequently Asked Questions

What is CVE-2026-78006? A CVSS 9.8 deserialization vulnerability (CWE-502) in The Events Calendar, a WordPress plugin from StellarWP, that NVD states allows unauthenticated remote code execution in versions through 6.17.4.

Is CVE-2026-78006 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 12, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration. Treat it as reported exploitation, not confirmed.

Do I need comments enabled for my site to be at risk? Yes. NVD’s description states the attack chain requires comments to be enabled and visible on event posts — the moderation-hash URL WordPress exposes for pending comments is how the malicious payload reaches the vulnerable code path without authentication.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed. The severity case stands independently of that.

Is this the same bug as CVE-2026-78159? No, but they’re closely related. Both bypass the plugin’s is_safe_widget_instance() safety check, disclosed and patched on the same day — this one through PHP’s pre-parse magic-method behavior combined with a forged integrity hash, CVE-2026-78159 through a different validation gap in a related function. Patching one does not confirm the other is fixed; check both.


Severity, vector, weakness classification, mechanism, and affected-version ceiling sourced from the National Vulnerability Database record for CVE-2026-78006. Exploitation status and the September 12, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools