What happened
A security weakness in The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all is being tracked as CVE-2026-78159. The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6 17 3 via the parse_array function. The affected release boundary in the available advisory material is up to, and including, 6.17.3 via the parse_array f The Events Calendar plugin for WordPress; teams should compare that boundary with the versions actually running in production.
The flaw is best understood as a code-execution weakness, rather than simply as a CVE number or severity score. If the published conditions are met, the security consequence is attacker-controlled code execution.
Organizations using The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all should identify affected versions, map where the vulnerable function is reachable and understand what the affected process can access. The important point is that running an affected version of The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all creates exposure, while an actual compromise still depends on whether the attacker can reach the trigger conditions described above.
The available advisory information identifies up to, and including, 6 17 3 via the parse_array f The Events Calendar plugin for WordPress as affected versions. CVE-2026-78159 currently carries a CRITICAL 9 8 severity signal in the retained vulnerability data. The reported consequence is code execution, meaning successful exploitation could make the affected application or process run attacker-controlled code.
The documented consequence includes code execution, so successful exploitation can move the issue from malformed input to attacker activity inside the affected process. Successful exploitation could let an attacker run code on a vulnerable system, which can lead to broader compromise depending on the privileges of the affected service. The issue currently carries a CRITICAL 9 8 severity signal in the CyberDeltaForce record.
The operational question is not simply the severity score, but whether the affected component is deployed, reachable, business-critical and protected by compensating controls. The current severity assessment is CRITICAL 9 8. Real risk depends on exposure, exploitability, compensating controls and the importance of the affected asset—not the CVSS number alone.
No exploitation flag is present in the retained CyberDeltaForce data at this time; that status can change as vendor and threat-intelligence reporting develops. Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present. Apply the vendor patch or mitigation for CVE-2026-78159 and validate the affected path after remediation.
The current source set does not report active exploitation of CVE-2026-78159; that status should be monitored rather than treated as proof that exploitation is impossible. The most useful validation after remediation is to confirm that the vulnerable path no longer permits the reported behavior and that the deployed release matches the vendor's corrected version.
So far, researchers have not reported exploitation, but that can change as vendor, government or threat-intelligence reporting develops.
Reference sources
Reporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.
What security teams should do now
- Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.
- Apply the vendor patch or mitigation for CVE-2026-78159 and validate the affected path after remediation.
What is not yet confirmed
- So far, researchers have not reported exploitation, but that can change as vendor, government or threat-intelligence reporting develops.