CVE-2026-78159 | StellarWP The Events Calendar Plugin up to 6.17.3 on WordPress Widget Classes parse_array classes code injection
A vulnerability was found in StellarWP The Events Calendar Plugin up to 6.17.3 on WordPress. It has been declared as critical. This issue affects the function Element_Classes::parse_array of the component Widget Classes. Executing a manipulation of the argument classes can lead to code injection.
This vulnerability is handled as CVE-2026-78159. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More