The Events Calendar: two 9.8 flaws let a blog comment take over 600,000+ sites
Published · Disclosed September 14, 2026 · Reviewed by Adam Taylor
| Plugin | Vulnerable | Fixed in |
|---|---|---|
| The Events Calendar | <= 6.17.4 | 6.17.4.1 |
If your site lists events, meetups, or classes, this one is worth a look today. Wordfence’s Argus research tool found two separate ways to take over a site running The Events Calendar, a plugin used on more than 600,000 WordPress sites, and neither one needs a password.
Both are scored 9.8 out of 10. The fix landed in version 6.17.4.1, released September 10.
Am I affected?
You’re affected if your site runs The Events Calendar 6.17.4 or earlier. Check the version under Plugins in your dashboard.
You don’t need to have done anything unusual to be exposed. Both flaws sit in how the plugin handles comments on event pages, a feature that’s normally on by default.
What an attacker could do
An attacker leaves a comment on one of your event listings, no account required. That alone starts the attack:
- One path (CVE-2026-78006) uses the comment to smuggle in a piece of data that WordPress later rebuilds into a live code object, letting the attacker run commands on your server directly.
- The other (CVE-2026-78159) abuses the same comment-handling code to reset the site administrator’s password, which opens the door to installing a malicious plugin and full takeover from there.
Neither needs the comment to be approved, and neither needs a logged-in visitor to click anything. From there, the usual damage follows: admin accounts, backdoors, database access, spam, or a defaced site.
What to do
- Update The Events Calendar to 6.17.4.1 or later today. Plugins → Update.
- Check your users list under Users for administrators you don’t recognize, especially any created recently.
- Look through recent comments on event pages for anything that looks like junk data rather than an actual comment.
- If you find anything odd, don’t stop at deleting it. The account or comment is usually just the visible trace; whatever let the attacker back in tends to stay behind. Get the site checked properly.
There’s no confirmed exploitation in the wild yet, but the bar here is unusually low: no account, no click, just a comment. That combination tends to get scanned for fast once it’s public.
On a Protect plan? Plugin updates are part of what we do, so this one is covered.