2 Critical Calendar WordPress Plugin Flaws Put 600K Sites at Risk of Takeover
Élevé · Hackread ·
WordPress
Ce qui s'est passé
Two critical unauthenticated RCE flaws (CVSS 9.8) in The Events Calendar WordPress plugin put 600,000+ sites at risk of full takeover. No CVE IDs listed; verify with the vendor advisory.
À faire maintenant
Update The Events Calendar plugin to the latest patched release now. If no patch exists, deactivate and remove the plugin. Then scan logs and files for compromise indicators and review admin accounts.
Source originale
Analyse assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.