Skip to content

The Events Calendar Remote Code Execution

Wordfence September 12, 2026

As a reminder, the Wordfence Intelligence Vulnerability Database API is completely free to query and utilize, both personally and commercially, and contains all the same vulnerability data as the user interface. Please review the API documentation and Webhook documentation for more information on how to query the vulnerability API endpoints and configure webhooks utilizing all the same data present in the Wordfence Intelligence user interface.

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached. This makes it possible for unauthenticated attackers to execute code on the server. This is exploitable without authentication or approval because the plugin's V2 single-event template runs do_blocks() over buffered HTML, and WordPress returns a moderation-hash URL that allows an unauthenticated commenter to immediately view their own pending , delivering the injected block markup to the vulnerable code path before any moderation occurs. This does require to be enabled and visible on events.

Wordfence blocked 723 attacks targeting this vulnerability in the past 24 hours.

plugins.trac.wordpress.org

plugins.trac.wordpress.org

plugins.trac.wordpress.org

plugins.trac.wordpress.org

plugins.trac.wordpress.org

plugins.trac.wordpress.org

Vulnerability Details for The Events Calendar

Recent vulnerabilities in The Events Calendar

This record contains material that is subject to copyright.

-2026 Defiant Inc.

-2026 The MITRE Corporation

Have information to add, or spot any errors? us at [email protected] so we can make any appropriate adjustments.

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Want to get notified of the latest vulnerabilities that may affect your WordPress site? Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Extracted Entities