2 Critical Calendar WordPress Plugin Flaws Put 600K Sites at Risk of Takeover
High · Hackread ·
WordPress
What happened
Two critical unauthenticated RCE flaws (CVSS 9.8) in The Events Calendar WordPress plugin put 600,000+ sites at risk of full takeover. No CVE IDs listed; verify with the vendor advisory.
What to do now
Update The Events Calendar plugin to the latest patched release now. If no patch exists, deactivate and remove the plugin. Then scan logs and files for compromise indicators and review admin accounts.
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.