All coverage
CVE-2026-78159: CRITICAL RCE in The Events Calendar (<=6.17.3). Unauthenticated attackers can run arbitrary code via crafted comments. Disable comments on tribe_events posts to mitigate. CVSS 9.8. Details: https:// radar.offseq.com/threat/cve-20 26-78159-cwe-94-improper-control-of-generation-of-code-code-injection-in-stellarwp-the-events-c0d168b99a9315ff # OffSeq # WordPress # Infosec # RCE
CVE-2026-78006: CRITICAL RCE in The Events Calendar plugin (<=6.17.4) for WordPress. Unauthenticated attackers can exploit comments to run code on the server. Disable event comments now & check for patches. https:// radar.offseq.com/threat/cve-20 26-78006-cwe-502-deserialization-of-untrusted-data-in-stellarwp-the-events-calendar-efa20e86741ba4b3 # OffSeq # WordPress # RCE # Vuln
WP images upload on piclect (≤1.0) suffers from CRITICAL CVE-2026-84171: Unauthenticated attackers can upload arbitrary files, risking code execution. Restrict uploads & monitor activity until a fix is released. https:// radar.offseq.com/threat/cve-20 26-84171-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-wp-images-upload-on-piclect-1bdb1fa95a2cb1f8 # OffSeq # WordPress # CVE202684171
CVE-2026-78006: The Events Calendar plugin ≤6.17.4 has a CRITICAL RCE flaw. Unauthenticated attackers can run code via comment handling — disable event comments until patched. Review vendor advisories. https:// radar.offseq.com/threat/the-th e-events-calendar-plugin-for-wordpress-is-vulnerable-to-remote-code-execution-in-all-versions-up-6446d1c8dfcb6a24 # OffSeq # WordPress # CVE202678006 # RCE
CVE-2026-78159: The Events Calendar <=6.17.3 for WordPress has a CRITICAL RCE flaw via parse_array(). Unauthenticated code execution if comments on tribe_events posts are enabled. Disable comments as interim mitigation. https:// radar.offseq.com/threat/the-th e-events-calendar-plugin-for-wordpress-is-vulnerable-to-remote-code-execution-in-all-versions-up-1ecd7d8aa73f934d # OffSeq # WordPress # RCE