Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin
Wordfence Argus found two critical unauthenticated RCE vulnerability chains in The Events Calendar WordPress plugin, active on over 600,000 sites.
Wordfence Argus identified two independent critical vulnerability chains in The Events Calendar WordPress plugin on August 21-22, 2026. Both chains originate in the plugin's widget-rendering pipeline and can lead to unauthenticated Remote Code Execution via two separate methods. The plugin is active on more than 600,000 websites.
- Two independent unauthenticated vulnerability chains leading to RCE
- Both chains begin in the widget-rendering pipeline
- Plugin active on over 600,000 websites
- Discovered by Wordfence Argus on August 21-22, 2026
On August 21 and August 22, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability chains in The Events Calendar, a WordPress plugin active on more than 600,000 websites. Both chains begin in the plugin's widget-rendering pipeline and can ultimately lead to Remote Code Execution without authentication through two separate methods. The post Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin appeared first on Wordfence.
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at wordfence.com.