{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/the-events-calendar/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:theeventscalendar:the_events_calendar:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-78006"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["The Events Calendar (\u003c= 6.17.4)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["The Events Calendar"],"content_html":"\u003cp\u003eThe Events Calendar plugin for WordPress is vulnerable to Remote Code Execution (CVE-2026-78006) in all versions up to and including 6.17.4. The vulnerability stems from insufficient protection within the \u003ccode\u003eis_safe_widget_instance\u003c/code\u003e function, which can be bypassed because PHP executes magic methods during pre-parsing. When combined with \u003ccode\u003eenable_rendering_widget_copied()\u003c/code\u003e, an attacker can forge a valid \u003ccode\u003ewp_hash\u003c/code\u003e integrity attribute prior to reaching an \u003ccode\u003eunserialize()\u003c/code\u003e call.\u003c/p\u003e\n\u003cp\u003eThe flaw is reachable by unauthenticated attackers because the plugin's V2 single-event template executes \u003ccode\u003edo_blocks()\u003c/code\u003e on buffered comment HTML. WordPress provides a moderation-hash URL that allows an unauthenticated user to view their own pending comment immediately. An attacker can leverage this to deliver malicious block markup to the vulnerable code path before any administrative moderation occurs. This attack requires the target WordPress instance to have comments enabled and visible on event pages. Successful exploitation allows for unauthenticated code execution on the underlying web server.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress instance running a vulnerable version of The Events Calendar with comment functionality enabled on event pages.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload disguised as block markup intended to trigger the deserialization flaw.\u003c/li\u003e\n\u003cli\u003eAttacker submits a new comment on an event page containing the malicious payload.\u003c/li\u003e\n\u003cli\u003eAttacker utilizes the WordPress moderation-hash URL to access and trigger the rendering of their own pending comment.\u003c/li\u003e\n\u003cli\u003eThe plugin's V2 single-event template calls \u003ccode\u003edo_blocks()\u003c/code\u003e on the buffered comment HTML during the rendering process.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eis_safe_widget_instance\u003c/code\u003e function is invoked, and the attacker-forged \u003ccode\u003ewp_hash\u003c/code\u003e attribute bypasses existing integrity checks.\u003c/li\u003e\n\u003cli\u003eThe application reaches the \u003ccode\u003eunserialize()\u003c/code\u003e function with the attacker-controlled input, leading to arbitrary code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-78006 allows unauthenticated attackers to execute arbitrary code with the privileges of the web server process. This can lead to full site compromise, data exfiltration, and lateral movement within the hosting environment. All WordPress sites utilizing The Events Calendar version 6.17.4 or earlier are at risk if comments are enabled on event pages.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update The Events Calendar plugin to the latest version, ensuring all installations are beyond version 6.17.4.\u003c/li\u003e\n\u003cli\u003eAs a temporary mitigation, disable comments on all event-related posts until the plugin has been patched.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for suspicious HTTP POST requests directed toward comment submission endpoints that contain unexpected block-like serialized strings or PHP magic method patterns.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-12T09:18:42Z","date_published":"2026-09-12T09:18:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-events-calendar-rce/","summary":"An unauthenticated remote code execution vulnerability (CVE-2026-78006) exists in The Events Calendar plugin for WordPress due to insecure deserialization in the is_safe_widget_instance function.","title":"Remote Code Execution in The Events Calendar WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-events-calendar-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - The Events Calendar","version":"https://jsonfeed.org/version/1.1"}