Gbhackers iconGbhackersSep 15, 2026

WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites

Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could allow attackers to execute code and fully compromise affected websites remotely. These flaws, identified by Wordfence Argus, impact plugin versions up to 6.17.4 and have been patched in version 6.17.4.1.

WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites

Share this story

Send the public story page.

Useful takeaways from this story.

Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could allow attackers to execute code and fully compromise affected websites remotely.

These flaws, identified by Wordfence Argus, impact plugin versions up to 6.17.4 and have been patched in version 6.17.4.1.

The Events Calendar is active on over 600,000 WordPress websites, […]

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could allow attackers to execute code and fully compromise affected websites remotely. These flaws, identified by Wordfence Argus, impact plugin versions up to 6.17.4 and have been patched in version 6.17.4.1. The Events Calendar is active on over 600,000 WordPress websites, […]

Details worth keeping

The Events Calendar is active on over 600,000 WordPress websites, […]

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app