CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7489

As cited

Copy frozen at (site build).

vulnerabilities

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

The Events Calendar plugin for WordPress contains unauthenticated remote code execution (RCE) vulnerabilities that could allow attackers to compromise affected sites. An estimated 200,000 or more WordPress installations running the plugin are potentially at risk of takeover.

Why it matters: WordPress site operators using The Events Calendar plugin must patch immediately to prevent unauthorized access and system compromise by unauthenticated attackers.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary