THREAT OPS › Threat News › Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin
Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin
<p>On August 21 and August 22, 2026, <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" rel="noopener" target="_blank">Wordfence Argus</a>, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability chains in <a href="https://wordpress.org/plugins/the-events-calendar/" rel="noopener" target="_blank">The Events Calendar</a>,
MITRE ATT&CK techniques
Indicators of compromise
- 9bf72594e071c28445ed7a1be0de1a23md5
- f97767e14ecb84ebfb6efdeaad2ee129md5
- CVE-2026-78006cve
- CVE-2026-78159cve
- https://wordpress.org/plugins/the-events-calendar/url
- https://wordpress.org/plugins/wordfence/url
- https://stellarwp.com/url
- https://www.cve.org/CVERecord?id=CVE-2026-78006url
- https://www.cve.org/CVERecord?id=CVE-2026-78159url
- 6.17.4.1ipv4
- 6.17.3.1ipv4
- www.gravatar.comdomain