Critical RCE Vulnerability in The Events Calendar Plugin for WordPress
Article Content
- •The Events Calendar plugin is vulnerable to RCE in versions up to 6.17.4.
- •Exploits can be executed by unauthenticated attackers via the is_safe_widget_instance function.
- •723 attacks targeting this vulnerability were blocked by Wordfence in the last 24 hours.
The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution (RCE) in all versions up to and including 6.17.4. This vulnerability arises from the is_safe_widget_instance function, which lacks sufficient protection, allowing unauthenticated attackers to execute code on the server. The exploit can be triggered through the plugin's V2 single-event template, which processes buffered HTML without proper moderation. Wordfence reported blocking 723 attacks targeting this vulnerability within the last 24 hours. The vulnerability is categorized under CVE-2026-6174. Users of the plugin are urged to update to the latest version to mitigate risks. As of now, no active exploitation has been confirmed, but the potential for exploitation is significant due to the nature of the vulnerability.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…