2 Critical Calendar WordPress Plugin Flaws Put 600K Sites at Risk of Takeover

High · Hackread ·

WordPress

What happened

Two critical unauthenticated RCE flaws (CVSS 9.8) in The Events Calendar WordPress plugin put 600,000+ sites at risk of full takeover. No CVE IDs listed; verify with the vendor advisory.

What to do now

Update The Events Calendar plugin to the latest patched release now. If no patch exists, deactivate and remove the plugin. Then scan logs and files for compromise indicators and review admin accounts.

Original source

Hackread

AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news