logo

Hackers target WordPress calendar plugin used by 150,000 sites

ID: 8bc1b589-1bef-514c-9a2a-93b70d35a94c

STIX ID: report--8bc1b589-1bef-514c-9a2a-93b70d35a94c

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-07-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A high-severity vulnerability (CVE-2024-5441, CVSS 8.8) in the Modern Events Calendar WordPress plugin permits arbitrary file uploads (including PHP) via the set_featured_image flow, enabling remote code execution and site takeover on affected versions (≤7.11.0); over 150,000 sites may be impacted, Wordfence observed active exploitation attempts and Webnus released version 7.12.0 to patch the issue—users should upgrade or disable the plugin immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.