{"id":11947,"date":"2026-09-17T13:42:13","date_gmt":"2026-09-17T19:42:13","guid":{"rendered":"https:\/\/beaconlab.us\/publicacion\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/"},"modified":"2026-09-29T09:59:06","modified_gmt":"2026-09-29T15:59:06","slug":"alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress","status":"publish","type":"publicacion","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/","title":{"rendered":"Alert 2026-102 Critical Vulnerabilities in The Events Calendar plugin for WordPress"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Affected product(s):<\/h2>\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Product<\/strong><\/td><td><strong>CVE<\/strong><\/td><td><strong>Affected versions<\/strong><\/td><td><strong>Fixed version<\/strong><\/td><\/tr><tr><td><strong>The Events Calendar for WordPress<\/strong><\/td><td>CVE\u20112026\u201178159<\/td><td>Up to 6.17.3, inclusive<\/td><td>6.17.3.1 or later<\/td><\/tr><tr><td><strong>The Events Calendar for WordPress<\/strong><\/td><td>CVE\u20112026\u201178006<\/td><td>Up to 6.17.4, inclusive<\/td><td>6.17.4.1 or later<\/td><\/tr><tr><td><strong>The Events Calendar for WordPress<\/strong><\/td><td>Both vulnerabilities<\/td><td>Versions prior to 6.17.4.1<\/td><td>6.17.4.1 or later<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<p class=\"has-small-font-size wp-block-paragraph\">*Version <strong>6.17.4.1<\/strong>, released on September 10, 2026, is the first release that contains fixes for both vulnerabilities.<\/p>\n\n<h2 class=\"wp-block-heading\">Description<\/h2>\n\n<p class=\"wp-block-paragraph\">Two critical remote code execution (RCE) vulnerabilities were identified in the <strong>The Events Calendar<\/strong> plugin for WordPress, developed by StellarWP. The flaws, <strong>CVE\u20112026\u201178006<\/strong> and <strong>CVE\u20112026\u201178159<\/strong>, have a <strong>CVSS 9.8<\/strong> score and allow remote unauthenticated attackers to take control of vulnerable sites under certain conditions, without requiring registration, login, or victim interaction.<\/p>\n\n<p class=\"wp-block-paragraph\">The plugin has more than <strong>600,000 active installations<\/strong>. StellarWP published fixes for both vulnerability chains; it is recommended to update immediately to <strong>The Events Calendar 6.17.4.1 or a later version<\/strong> and perform a review for possible compromise, especially if the site allows comments on individual event pages.<\/p>\n\n<p class=\"wp-block-paragraph\">The vulnerabilities are located in the widget rendering process of The Events Calendar, particularly when the plugin processes content from an individual event page, including comments pending moderation. The attacker does not need the comment to be approved: WordPress allows whoever published a comment to view their own pending comment through a moderation link, which can cause attacker-controlled content to reach the vulnerable plugin logic.<\/p>\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>CVE<\/strong><\/td><td><strong>CVSS<\/strong><\/td><td><strong>Type<\/strong><\/td><td><strong>Main condition<\/strong><\/td><td><strong>Impact<\/strong><\/td><\/tr><tr><td><strong>CVE\u20112026\u201178006<\/strong><\/td><td>9.8 \u2014 Critical<\/td><td>PHP Object Injection<\/td><td>Comments enabled on event pages and &#8220;Show comments on event pages&#8221; option active<\/td><td>Execution of system commands and RCE with permissions of the web server user<\/td><\/tr><tr><td><strong>CVE\u20112026\u201178159<\/strong><\/td><td>9.8 \u2014 Critical<\/td><td>Code injection via <em>callable invocation<\/em> \/ insufficient validation<\/td><td>Processing of controlled content within event widgets<\/td><td>Administrative password reset, admin access, and subsequent RCE<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<h2 class=\"wp-block-heading\">Solution<\/h2>\n\n<p class=\"wp-block-paragraph\">The definitive solution is to update <strong>The Events Calendar<\/strong> to version <strong>6.17.4.1 or later<\/strong>:<\/p>\n\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-plugin-directory wp-block-embed-plugin-directory\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"YADoYTroUy\"><a href=\"https:\/\/wordpress.org\/plugins\/the-events-calendar\/\">The Events Calendar<\/a><\/blockquote><iframe class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; visibility: hidden;\" title=\"\u201cThe Events Calendar\u201d \u2014 Plugin Directory\" src=\"https:\/\/wordpress.org\/plugins\/the-events-calendar\/embed\/#?secret=8Z4vQgq35R#?secret=YADoYTroUy\" data-secret=\"YADoYTroUy\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe>\n<\/div><\/figure>\n\n<p class=\"wp-block-paragraph\">Since it is a critical RCE, easy to exploit, it is recommended after updating to follow the following verification steps:<\/p>\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Purge WordPress, PHP, CDN, and WAF caches to ensure the updated code is loaded.<\/li>\n\n\n\n<li>Confirm that comments are not enabled on event pages if that functionality is not required.<\/li>\n\n\n\n<li>Review administrative accounts, plugins, files, and logs to rule out prior exploitation.<\/li>\n\n\n\n<li>If signs of compromise are identified, isolate the site, preserve evidence, restore from a trusted backup, and rotate credentials for WordPress, hosting, database, SFTP\/SSH, APIs, and integrated services.<\/li>\n<\/ol>\n\n<h2 class=\"wp-block-heading\">Additional information:<\/h2>\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.wordfence.com\/blog\/2026\/09\/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin\/\" target=\"_blank\" rel=\"noopener\">Wordfence \u2014 Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/the-events-calendar\/the-events-calendar-6173-unauthenticated-code-injection-to-remote-code-execution-via-widget-classes-map-callable-invocation\" target=\"_blank\" rel=\"noopener\">Wordfence Intelligence \u2014 CVE\u20112026\u201178159<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.securityweek.com\/unauthenticated-rce-flaws-could-expose-200000-wordpress-sites-to-takeover\/\" target=\"_blank\" rel=\"noopener\">SecurityWeek \u2014 Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/cybersecuritynews.com\/critical-wordpress-plugin-flaws\/\" target=\"_blank\" rel=\"noopener\">Cyber Security News \u2014 Critical WordPress Plugin Flaws Put Over 600,000 Websites at Risk of Takeover<\/a><\/li>\n<\/ul>\n","protected":false},"featured_media":11762,"template":"","class_list":["post-11947","publicacion","type-publicacion","status-publish","has-post-thumbnail","hentry"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Affected product(s): *Version 6.17.4.1, released on September 10, 2026, is the first release that contains fixes for both vulnerabilities. Description Two critical remote code execution (RCE) vulnerabilities were identified in the The Events Calendar plugin for WordPress, developed by StellarWP. The flaws, CVE\u20112026\u201178006 and CVE\u20112026\u201178159, have a CVSS 9.8 score and allow remote unauthenticated attackers\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Beacon Lab - CSIRT by Cybolt\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Alert 2026-102 Critical Vulnerabilities in The Events Calendar plugin for WordPress - Beacon Lab\" \/>\n\t\t<meta property=\"og:description\" content=\"Affected product(s): *Version 6.17.4.1, released on September 10, 2026, is the first release that contains fixes for both vulnerabilities. Description Two critical remote code execution (RCE) vulnerabilities were identified in the The Events Calendar plugin for WordPress, developed by StellarWP. The flaws, CVE\u20112026\u201178006 and CVE\u20112026\u201178159, have a CVSS 9.8 score and allow remote unauthenticated attackers\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/wordpress-plugins-logo.jpeg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/wordpress-plugins-logo.jpeg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"500\" \/>\n\t\t<meta property=\"og:image:height\" content=\"500\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-09-17T19:42:13+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-29T15:59:06+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Alert 2026-102 Critical Vulnerabilities in The Events Calendar plugin for WordPress - Beacon Lab\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Affected product(s): *Version 6.17.4.1, released on September 10, 2026, is the first release that contains fixes for both vulnerabilities. Description Two critical remote code execution (RCE) vulnerabilities were identified in the The Events Calendar plugin for WordPress, developed by StellarWP. The flaws, CVE\u20112026\u201178006 and CVE\u20112026\u201178159, have a CVSS 9.8 score and allow remote unauthenticated attackers\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/wordpress-plugins-logo.jpeg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\\\/#listItem\",\"name\":\"Alert 2026-102 Critical Vulnerabilities in The Events Calendar plugin for WordPress\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\\\/#listItem\",\"position\":2,\"name\":\"Alert 2026-102 Critical Vulnerabilities in The Events Calendar plugin for WordPress\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"telephone\":\"+528007374357\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.mx\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/BeaconLab_V2-03.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/BeaconLabMX\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/beaconlabmx\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\\\/#webpage\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\\\/\",\"name\":\"Alert 2026-102 Critical Vulnerabilities in The Events Calendar plugin for WordPress - Beacon Lab\",\"description\":\"Affected product(s): *Version 6.17.4.1, released on September 10, 2026, is the first release that contains fixes for both vulnerabilities. Description Two critical remote code execution (RCE) vulnerabilities were identified in the The Events Calendar plugin for WordPress, developed by StellarWP. The flaws, CVE\\u20112026\\u201178006 and CVE\\u20112026\\u201178159, have a CVSS 9.8 score and allow remote unauthenticated attackers\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\\\/#breadcrumblist\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/wordpress-plugins-logo.jpeg\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\\\/#mainImage\",\"width\":500,\"height\":500},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\\\/#mainImage\"},\"datePublished\":\"2026-09-17T13:42:13-06:00\",\"dateModified\":\"2026-09-29T09:59:06-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Alert 2026-102 Critical Vulnerabilities in The Events Calendar plugin for WordPress - Beacon Lab","description":"Affected product(s): *Version 6.17.4.1, released on September 10, 2026, is the first release that contains fixes for both vulnerabilities. Description Two critical remote code execution (RCE) vulnerabilities were identified in the The Events Calendar plugin for WordPress, developed by StellarWP. The flaws, CVE\u20112026\u201178006 and CVE\u20112026\u201178159, have a CVSS 9.8 score and allow remote unauthenticated attackers","canonical_url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","position":1,"name":"Home","item":"https:\/\/beaconlab.us\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/#listItem","name":"Alert 2026-102 Critical Vulnerabilities in The Events Calendar plugin for WordPress"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/#listItem","position":2,"name":"Alert 2026-102 Critical Vulnerabilities in The Events Calendar plugin for WordPress","previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","name":"Home"}}]},{"@type":"Organization","@id":"https:\/\/beaconlab.us\/en\/#organization","name":"Beacon Lab","description":"CSIRT by Cybolt","url":"https:\/\/beaconlab.us\/en\/","telephone":"+528007374357","logo":{"@type":"ImageObject","url":"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/#organizationLogo"},"image":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/#organizationLogo"},"sameAs":["https:\/\/twitter.com\/BeaconLabMX","https:\/\/www.linkedin.com\/showcase\/beaconlabmx"]},{"@type":"WebPage","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/#webpage","url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/","name":"Alert 2026-102 Critical Vulnerabilities in The Events Calendar plugin for WordPress - Beacon Lab","description":"Affected product(s): *Version 6.17.4.1, released on September 10, 2026, is the first release that contains fixes for both vulnerabilities. Description Two critical remote code execution (RCE) vulnerabilities were identified in the The Events Calendar plugin for WordPress, developed by StellarWP. The flaws, CVE\u20112026\u201178006 and CVE\u20112026\u201178159, have a CVSS 9.8 score and allow remote unauthenticated attackers","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/#website"},"breadcrumb":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/#breadcrumblist"},"image":{"@type":"ImageObject","url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/wordpress-plugins-logo.jpeg","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/#mainImage","width":500,"height":500},"primaryImageOfPage":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/#mainImage"},"datePublished":"2026-09-17T13:42:13-06:00","dateModified":"2026-09-29T09:59:06-06:00"},{"@type":"WebSite","@id":"https:\/\/beaconlab.us\/en\/#website","url":"https:\/\/beaconlab.us\/en\/","name":"Beacon Lab","description":"CSIRT by Cybolt","inLanguage":"en-US","publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"Beacon Lab - CSIRT by Cybolt","og:type":"article","og:title":"Alert 2026-102 Critical Vulnerabilities in The Events Calendar plugin for WordPress - Beacon Lab","og:description":"Affected product(s): *Version 6.17.4.1, released on September 10, 2026, is the first release that contains fixes for both vulnerabilities. Description Two critical remote code execution (RCE) vulnerabilities were identified in the The Events Calendar plugin for WordPress, developed by StellarWP. The flaws, CVE\u20112026\u201178006 and CVE\u20112026\u201178159, have a CVSS 9.8 score and allow remote unauthenticated attackers","og:url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/","og:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/wordpress-plugins-logo.jpeg","og:image:secure_url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/wordpress-plugins-logo.jpeg","og:image:width":500,"og:image:height":500,"article:published_time":"2026-09-17T19:42:13+00:00","article:modified_time":"2026-09-29T15:59:06+00:00","twitter:card":"summary_large_image","twitter:site":"@BeaconLabMX","twitter:title":"Alert 2026-102 Critical Vulnerabilities in The Events Calendar plugin for WordPress - Beacon Lab","twitter:description":"Affected product(s): *Version 6.17.4.1, released on September 10, 2026, is the first release that contains fixes for both vulnerabilities. Description Two critical remote code execution (RCE) vulnerabilities were identified in the The Events Calendar plugin for WordPress, developed by StellarWP. The flaws, CVE\u20112026\u201178006 and CVE\u20112026\u201178159, have a CVSS 9.8 score and allow remote unauthenticated attackers","twitter:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/09\/wordpress-plugins-logo.jpeg"},"aioseo_meta_data":{"post_id":"11947","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-09-29 15:58:47","updated":"2026-09-29 16:38:56","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAlert 2026-102 Critical Vulnerabilities in The Events Calendar plugin for WordPress\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/beaconlab.us\/en\/"},{"label":"Alert 2026-102 Critical Vulnerabilities in The Events Calendar plugin for WordPress","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-102-critical-vulnerabilities-in-the-events-calendar-plugin-for-wordpress\/"}],"_links":{"self":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/11947","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion"}],"about":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/types\/publicacion"}],"version-history":[{"count":1,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/11947\/revisions"}],"predecessor-version":[{"id":11948,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/11947\/revisions\/11948"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media\/11762"}],"wp:attachment":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media?parent=11947"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}