Two independent critical vulnerability chains have been uncovered in The Events Calendar, a WordPress plugin active on more than 600,000 websites. Both chains begin in the plugin’s widget-rendering pipeline and can lead to Remote Code Execution without authentication through two separate methods.
More details can be found here: https://www.wordfence.com/blog/2026/09/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/
Dan Moore, Sr. Director CIAM Strategy at FusionAuth, provided the following comments:
“The WordPress Events Calendar RCE vulnerabilities both allow arbitrary commands through specially crafted payloads. This allows attackers to access elevated privileges, either directly against the filesystem or through WP admin commands.
This is, to put it technically, bad. In one case, they were able to reset admin passwords by calling WordPress functions with elevated privileges. Resetting account credentials, especially of admin users, should require proper authentication and authorization to prevent this kind of account takeover.”
As a WordPress users, I will check my WordPress hosted instance to see if I am affected. You should do the same ASAP.
Related
This entry was posted on September 16, 2026 at 8:33 am and is filed under Commentary. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Two Critical Vulnerability Chains Lead to RCE in WordPress Events Calendar Plugin
Two independent critical vulnerability chains have been uncovered in The Events Calendar, a WordPress plugin active on more than 600,000 websites. Both chains begin in the plugin’s widget-rendering pipeline and can lead to Remote Code Execution without authentication through two separate methods.
More details can be found here: https://www.wordfence.com/blog/2026/09/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/
Dan Moore, Sr. Director CIAM Strategy at FusionAuth, provided the following comments:
“The WordPress Events Calendar RCE vulnerabilities both allow arbitrary commands through specially crafted payloads. This allows attackers to access elevated privileges, either directly against the filesystem or through WP admin commands.
This is, to put it technically, bad. In one case, they were able to reset admin passwords by calling WordPress functions with elevated privileges. Resetting account credentials, especially of admin users, should require proper authentication and authorization to prevent this kind of account takeover.”
As a WordPress users, I will check my WordPress hosted instance to see if I am affected. You should do the same ASAP.
Share this:
Like this:
Related
This entry was posted on September 16, 2026 at 8:33 am and is filed under Commentary. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.