As cited
Copy frozen at (site build).
vulnerabilities
Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover
The Events Calendar plugin for WordPress contains unauthenticated remote code execution (RCE) vulnerabilities that could allow attackers to compromise affected sites. An estimated 200,000 or more WordPress installations running the plugin are potentially at risk of takeover.
Why it matters: WordPress site operators using The Events Calendar plugin must patch immediately to prevent unauthorized access and system compromise by unauthenticated attackers.
- Source published
- First seen by Cybersecurity Tracker