Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Crítico CVE-2026-78159 Multiple Vendors

RCE crítica en The Events Calendar para WordPress hasta v6.17.3

Vulnerabilidad · Publicado 12/09/2026

9.8
CVSS 3.x
04 Medio7 Alto9 Crítico10
Severidad: Crítico
Resumen ejecutivo

The Events Calendar plugin para WordPress es vulnerable a Ejecución Remota de Código (RCE) en todas las versiones hasta 6.17.3. La vulnerabilidad existe en la función parse_array() debido a validación insuficiente del mapa 'classes' del widget, permitiendo que payloads de arrays simples eluda el control is_safe_widget_instance() y alcance el punto de invocación de funciones. Afecta directamente a sitios WordPress en México y LATAM que utilizan este plugin popular para gestión de eventos.

Análisis asistido por IA, contexto LATAM revisado por el equipo 2MCI.

Descripción técnica

Descripción técnica

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the targeted site has comments enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted, as the attack chain is triggered when do_blocks() processes the single-event HTML including the comment area.

Puntuación CVSS

Score: 9.8/10 — Severidad: CRITICAL — Estado NIST: Received

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Debilidades (CWE)

CWE-94

Fuente oficial

Publicado en NIST NVD.

¿Qué hacer?
  • Actualizar inmediatamente The Events Calendar a versión superior a 6.17.3
  • Si no es posible actualizar, desactivar y eliminar el plugin hasta contar con parche
  • Revisar logs de acceso para detectar explotación previa (payloads en parámetros widget 'classes')
  • Aplicar restricciones de permisos en wp-admin y limitar acceso a editores de widgets
  • Consultar NIST NVD y proveedores de seguridad LATAM para actualizaciones de mitigaciones
Esta alerta fue generada automáticamente a partir del NVD del NIST.