Skip to content
Critical RCE Vulnerability in The Events Calendar Plugin for WordPress

Critical RCE Vulnerability in The Events Calendar Plugin for WordPress

First seen 13 Sep 2026, 02:40 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 13, 2026 at 03:42 UTC
  • The Events Calendar plugin is vulnerable to RCE in versions up to 6.17.4.
  • Exploits can be executed by unauthenticated attackers via the is_safe_widget_instance function.
  • 723 attacks targeting this vulnerability were blocked by Wordfence in the last 24 hours.

The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution (RCE) in all versions up to and including 6.17.4. This vulnerability arises from the is_safe_widget_instance function, which lacks sufficient protection, allowing unauthenticated attackers to execute code on the server. The exploit can be triggered through the plugin's V2 single-event template, which processes buffered HTML without proper moderation. Wordfence reported blocking 723 attacks targeting this vulnerability within the last 24 hours. The vulnerability is categorized under CVE-2026-6174. Users of the plugin are urged to update to the latest version to mitigate risks. As of now, no active exploitation has been confirmed, but the potential for exploitation is significant due to the nature of the vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-12
Vulnerability disclosed
Wordfence reported a critical RCE vulnerability in The Events Calendar plugin affecting versions up to 6.17.4.
Wordfence
2026-09-12
723 attacks blocked
Wordfence blocked 723 attempts to exploit the RCE vulnerability within 24 hours of disclosure.
Wordfence
2026-09-13
Further reporting on vulnerability
Buttondown highlighted the same RCE vulnerability in their daily CVE report, confirming its critical nature.
Buttondown

More articles in this cluster (5)