{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/the-events-calendar--6.17.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:modern_tribe:the_events_calendar:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-78159"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["The Events Calendar (\u003c= 6.17.3)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","cve","rce","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Modern Tribe"],"content_html":"\u003cp\u003eThe Events Calendar plugin for WordPress is vulnerable to an unauthenticated Remote Code Execution (RCE) flaw, tracked as CVE-2026-78159. This vulnerability affects all versions up to and including 6.17.3. The flaw resides within the \u003ccode\u003eElement_Classes::parse_array\u003c/code\u003e method, which fails to adequately validate the \u003ccode\u003ewidget 'classes'\u003c/code\u003e map.\u003c/p\u003e\n\u003cp\u003eAn attacker can supply a specially crafted \u003ccode\u003ewp:legacy-widget\u003c/code\u003e block within a comment on a \u003ccode\u003etribe_events\u003c/code\u003e post. This payload bypasses the \u003ccode\u003eis_safe_widget_instance()\u003c/code\u003e object validation check. When the WordPress \u003ccode\u003edo_blocks()\u003c/code\u003e function processes the page content - specifically including the comment section - it triggers a callable-invocation sink in the \u003ccode\u003eparse_array\u003c/code\u003e function, enabling arbitrary PHP code execution. This vulnerability is critical as it requires no authentication to exploit, relying only on the presence of comments on events posts.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary code on the underlying web server hosting the WordPress site. This can lead to full site compromise, data exfiltration, and the installation of persistent backdoors. Given the widespread use of The Events Calendar plugin, this vulnerability poses a high risk to organizations hosting event-driven content on WordPress.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate update of The Events Calendar plugin to the latest version (patching CVE-2026-78159). For instances where immediate patching is not possible, disable comments on all \u003ccode\u003etribe_events\u003c/code\u003e post types to break the exploitation vector. Monitor web server logs for HTTP POST requests directed at comment submission endpoints that contain serialized or legacy widget-related strings if WAF virtual patching is required.\u003c/p\u003e\n","date_modified":"2026-09-12T09:18:49Z","date_published":"2026-09-12T09:18:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-the-events-calendar-rce/","summary":"The Events Calendar plugin for WordPress is vulnerable to unauthenticated remote code execution via a flaw in the parse_array function that allows attackers to bypass security checks through crafted widget block comments.","title":"Remote Code Execution in The Events Calendar WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-the-events-calendar-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - The Events Calendar (\u003c= 6.17.3)","version":"https://jsonfeed.org/version/1.1"}