Overview
Two critical vulnerabilities in The Events Calendar, one of WordPress’s widely deployed plugins, could allow unauthenticated attackers to achieve remote code execution and potentially take control of vulnerable websites. The plugin currently has more than 600,000 active installations, according to WordPress.org, making the potential exposure significant. The vulnerabilities, tracked as CVE-2026-78006 and CVE-2026-78159, both carry CVSS scores of 9.8 Critical. The fully patched version is 6.17.4.1, released on 10 September 2026. For IT leaders, the incident highlights a much broader issue: your organisation’s website may be managed outside traditional IT infrastructure, but it can still represent a significant cybersecurity and reputational risk.
How the Vulnerabilities Work
Both vulnerabilities involve the way The Events Calendar processes widget-related content on event pages. CVE-2026-78006 affects versions up to 6.17.4 and can allow PHP object injection to develop into remote code execution. CVE-2026-78159 affects versions up to 6.17.3 and uses a separate code-injection path capable of reaching executable PHP functions. Both attack paths can be exploited without authentication under specific conditions involving comments being enabled on event pages. Successful exploitation could allow an attacker to execute commands on the web server, modify website content, install malware or potentially use the compromised server as a stepping stone toward other systems.
The Bigger Risk Is the Plugin Ecosystem
WordPress itself is only one component of a website. Modern websites frequently depend on numerous third-party plugins for calendars, forms, SEO, e-commerce, analytics, backups and other functionality. Every additional plugin introduces another piece of software that must be maintained, monitored and trusted. This creates what technology leaders should view as digital supply-chain risk. An organisation may invest heavily in firewalls, endpoint protection, MFA and cloud security while simultaneously operating an internet-facing website containing outdated or unnecessary third-party components. Attackers will naturally target whichever path provides the easiest access.
What Organisations Should Do
Administrators using The Events Calendar should update to version 6.17.4.1 or later immediately. WordPress.org confirms that the release strengthened validation of copied widget instances, addressing the affected functionality. Organisations should also review whether comments are required on event pages, remove plugins that are no longer necessary, verify administrator accounts, and review web-server and security logs for suspicious activity. More importantly, plugin management should become part of formal vulnerability management. Websites should have clear ownership, defined patching responsibilities, tested backups and monitoring rather than being treated as systems that only require attention when content needs changing.
Website Security Is a Business Risk
A compromised corporate website can result in far more than an embarrassing defacement. Attackers may redirect customers to malicious sites, steal information, distribute malware, damage search-engine reputation or use the infrastructure to launch additional attacks. For organisations involved in e-commerce, customer portals or online services, the impact can quickly extend into revenue loss, regulatory exposure and reputational damage. Leadership therefore needs visibility into who manages the organisation’s websites, what plugins are installed, who is responsible for updates and how quickly critical vulnerabilities can be remediated.
Expert in the Cloud Insight
The Events Calendar vulnerabilities demonstrate why cybersecurity cannot stop at servers, endpoints and cloud platforms. Every internet-facing application and every third-party component expands the organisation’s attack surface. WordPress plugins provide enormous flexibility, but that convenience creates an ongoing security responsibility. For CIOs and IT managers, the important question is not simply whether the website is online and functioning. It should also be: “Do we know what is running behind it, who is maintaining it, and how quickly we can respond when one component becomes vulnerable?” A small plugin can support a useful business function, but when compromised, it can also become the front door into a much larger security incident. Good cyber governance includes knowing what you run, why you run it, and who is responsible for keeping it secure.
Leave a Reply