Unauthenticated RCE in The Events Calendar Plugin Endangers 600K+ WordPress Sites

Élevé · Hackread ·

WordPress

En bref

  • The Events Calendar WordPress plugin has a critical vulnerability enabling remote code execution.
  • Attacks require no authentication and can lead to complete site takeover.
  • Over 600,000 websites use the affected plugin.
  • No CVE identifiers have been assigned yet.
  • Immediate patching or mitigation is strongly recommended.

A dangerous security weakness has been identified in a popular WordPress add-on called The Events Calendar. This plugin is used by a large number of websites to manage event listings. The flaw permits an attacker to execute arbitrary code on the server without needing any credentials. This means an unauthenticated user can potentially take full control of a vulnerable site.

The plugin is installed on more than six hundred thousand WordPress sites. That includes small blogs, business sites, and possibly government or educational portals. Any site running a vulnerable version is at risk. Since the attack does not require login, even sites with strong password policies are exposed.

Successful exploitation leads to site takeover. An attacker could inject malicious scripts, steal data, deface the site, or use it to distribute malware. For K-12 and government entities, this could mean data breaches, service disruptions, and compliance violations. The lack of a CVE identifier does not reduce the threat; it may simply mean the disclosure process is still ongoing.

WordPress plugins are a common attack vector because they are often third-party and may not receive timely updates. The Events Calendar is widely deployed, making it a high-value target. Attackers frequently scan for known vulnerable plugins and automate exploitation. Even without a public CVE, proof-of-concept code may circulate in private channels.

Administrators should monitor for signs of compromise such as unexpected admin accounts, modified files, or outbound connections to unknown IPs. Keep an eye on vendor advisories for a patch. Until then, consider virtual patching through a web application firewall. Also watch for any increase in scanning activity targeting the plugin's endpoints.

À faire maintenant

  1. Immediately check if The Events Calendar is installed and update to the latest version if a patch is available.
  2. If no patch exists, deactivate and remove the plugin until a fix is released.
  3. Deploy a web application firewall (WAF) rule to block exploit attempts targeting the plugin.
  4. Audit your site for indicators of compromise: new admin users, unusual file changes, or suspicious outbound traffic.
  5. Restrict access to wp-admin and wp-login.php by IP address or add multi-factor authentication.
  6. Monitor logs for requests to plugin-specific endpoints and unusual POST requests.
  7. Apply the principle of least privilege to database and web server users to limit damage from any successful exploit.

Source originale

Hackread

Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber