Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover
ID: a8c32c39-225e-5119-95c8-b228dd27893e
STIX ID: report--a8c32c39-225e-5119-95c8-b228dd27893e
Feed Name: CosmicBytez Labs
The Events Calendar WordPress plugin (200,000+ installs) contains two critical unauthenticated RCE vulnerabilities—one in the widget template handling (fixed in 6.17.3.1) and one via PHP object injection in event comments (fixed in 6.17.4.1). Both can yield full admin takeover and arbitrary code execution; exploitation attempts have been observed, so site owners should immediately update to 6.17.4.1 or later, disable event comments as a temporary mitigation, audit for compromise, and deploy WAF rules where possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
