Summary
StellarWP patched two critical vulnerabilities in The Events Calendar plugin that allow unauthenticated attackers to execute remote code and take over WordPress sites. The flaws exploit the plugin's widget-rendering pipeline and can be triggered through unapproved comments.
Take Action:
If you run The Events Calendar plugin on WordPress, update it to version 6.17.4.1 or later immediately. The flaw lets an anonymous attacker take over your server just by leaving a comment. If you can't update immediately, turn off the "Show comments on event pages" option to block the attack until you update.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)