Skip to content
ThreatCluster

600K WordPress Sites at Risk from Critical Plugin Vulnerabilities

First seen 19 Sep 2026, 12:30 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 19, 2026 at 14:26 UTC
  • Two critical vulnerabilities in the Calendar WordPress plugin affect 600,000 sites.
  • Attackers can exploit these flaws for site takeover via improper input validation.
  • No patches are currently available, necessitating immediate action from site administrators.

Two critical vulnerabilities in the Calendar WordPress plugin have been discovered, affecting approximately 600,000 sites. The vulnerabilities, tracked as CVE-2026-1234 and CVE-2026-1235, allow attackers to take over sites by exploiting improper input validation. The vulnerabilities are particularly severe due to the widespread use of the plugin in various WordPress installations. As of September 16, 2026, no patches have been released, and the vulnerabilities remain unaddressed. Security experts recommend immediate action to mitigate risks, including disabling the plugin until a fix is available. The vulnerabilities were reported by Hackread, highlighting the urgency for site administrators to assess their exposure. The situation is compounded by the fact that many site owners may not be aware of the risks posed by outdated plugins. Current status indicates that exploitation in the wild is possible given the high number of affected sites.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
Vulnerabilities disclosed
CVE-2026-1234 and CVE-2026-1235 vulnerabilities in Calendar plugin reported, affecting 600,000 sites.
Hackread
Recent
Exploitation risk identified
Security experts warn that the vulnerabilities could be exploited in the wild, urging immediate action.
Hackread

More articles in this cluster (2)