THREATOPS
THREAT OPSThreat News › Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin

Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin

medwordfencePublished 2026-09-14

<p>On August 21 and August 22, 2026, <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/argus" rel="noopener" target="_blank">Wordfence Argus</a>, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability chains in <a href="https://wordpress.org/plugins/the-events-calendar/" rel="noopener" target="_blank">The Events Calendar</a>,

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.wordfence.com/blog/2026/09/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/