Hackers target WordPress calendar plugin used by 150,000 sites
ID: 8bc1b589-1bef-514c-9a2a-93b70d35a94c
STIX ID: report--8bc1b589-1bef-514c-9a2a-93b70d35a94c
Feed Name: Bleeping Computer
Threat Score
A high-severity vulnerability (CVE-2024-5441, CVSS 8.8) in the Modern Events Calendar WordPress plugin permits arbitrary file uploads (including PHP) via the set_featured_image flow, enabling remote code execution and site takeover on affected versions (≤7.11.0); over 150,000 sites may be impacted, Wordfence observed active exploitation attempts and Webnus released version 7.12.0 to patch the issue—users should upgrade or disable the plugin immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
