Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin
High · Wordfence ·
WordPress
What happened
Wordfence found two critical unauthenticated RCE vulnerability chains in The Events Calendar WordPress plugin, affecting 600,000+ sites via its widget-rendering pipeline.
What to do now
Update The Events Calendar to the latest patched version immediately; verify with vendor advisory. If no patch, disable the plugin or block widget endpoints via WAF. Scan for compromise.
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.