Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 13 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Stellarwp
Stellarwp the Events Calendar Wordpress Wordpress wordpress |
|
| Vendors & Products |
Stellarwp
Stellarwp the Events Calendar Wordpress Wordpress wordpress |
Sat, 12 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the targeted site has comments enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted, as the attack chain is triggered when do_blocks() processes the single-event HTML including the comment area. | |
| Title | The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation | |
| Weaknesses | CWE-94 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-09-14T16:10:33.540Z
Reserved: 2026-08-23T11:39:39.155Z
Link: CVE-2026-78159
Updated: 2026-09-14T16:10:29.880Z
Status : Deferred
Published: 2026-09-12T08:16:24.377
Modified: 2026-09-14T17:17:51.410
Link: CVE-2026-78159
No data.
OpenCVE Enrichment
Updated: 2026-09-14T16:45:05Z
-
CWE-94
Improper Control of Generation of Code ('Code Injection')