security1 publisher
An unapproved comment triggers RCE in The Events Calendar before moderation sees it
StellarWP split the fix across two releases, so a WordPress site updated on August 25 stayed open to CVE-2026-78006 until 6.17.4.1 shipped on September 10. Version data puts about 240,000 installs behind both bugs.
Publishers:securityweek.com
Reality
- Evidence58
- Adoption55
- Hype gap+25
- Incentives45
- Confidence55