600K WordPress Sites at Risk from Critical Plugin Vulnerabilities
Article Content
- •Two critical vulnerabilities in the Calendar WordPress plugin affect 600,000 sites.
- •Attackers can exploit these flaws for site takeover via improper input validation.
- •No patches are currently available, necessitating immediate action from site administrators.
Two critical vulnerabilities in the Calendar WordPress plugin have been discovered, affecting approximately 600,000 sites. The vulnerabilities, tracked as CVE-2026-1234 and CVE-2026-1235, allow attackers to take over sites by exploiting improper input validation. The vulnerabilities are particularly severe due to the widespread use of the plugin in various WordPress installations. As of September 16, 2026, no patches have been released, and the vulnerabilities remain unaddressed. Security experts recommend immediate action to mitigate risks, including disabling the plugin until a fix is available. The vulnerabilities were reported by Hackread, highlighting the urgency for site administrators to assess their exposure. The situation is compounded by the fact that many site owners may not be aware of the risks posed by outdated plugins. Current status indicates that exploitation in the wild is possible given the high number of affected sites.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…