Two Critical Vulnerability Chains Lead to RCE in WordPress Events Calendar Plugin 

Two independent critical vulnerability chains have been uncovered in The Events Calendar, a WordPress plugin active on more than 600,000 websites. Both chains begin in the plugin’s widget-rendering pipeline and can lead to Remote Code Execution without authentication through two separate methods.

More details can be found here: https://www.wordfence.com/blog/2026/09/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/

Dan Moore, Sr. Director CIAM Strategy at FusionAuth, provided the following comments:

“The WordPress Events Calendar RCE vulnerabilities both allow arbitrary commands through specially crafted payloads. This allows attackers to access elevated privileges, either directly against the filesystem or through WP admin commands.

This is, to put it technically, bad. In one case, they were able to reset admin passwords by calling WordPress functions with elevated privileges. Resetting account credentials, especially of admin users, should require proper authentication and authorization to prevent this kind of account takeover.”

As a WordPress users, I will check my WordPress hosted instance to see if I am affected. You should do the same ASAP.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading