Skip to content

security_identifier

CVE-2026-78006

Identifier for an unauthenticated remote code execution flaw in The Events Calendar WordPress plugin arising from insufficient protection in its is_safe_widget_instance check, rated CVSS 9.8.

Current clusters