← All posts

The Events Calendar Flaw: 600,000 WordPress Sites, No Login

· Watch on YouTube

Good morning. Here are the five WordPress security stories worth knowing about today.

First up, a critical problem in The Events Calendar. This plugin is running on more than 600,000 WordPress sites. Researchers found two separate vulnerabilities, both of which can lead to remote code execution, and an attacker doesn’t need to log in.

On vulnerable sites, a malicious comment on an event can trigger the attack. The comment doesn’t even need to be approved first. That means an attacker could potentially take control of the website.

The fix arrived in version 6.17.4.1, and the plugin has already moved on to version 6.17.5. So, if you use The Events Calendar, update it now. If comments are enabled on your events, I’d give this one priority, because this isn’t about stealing a little information. It’s about running code on your server.

Next up, a serious vulnerability in Tutor LMS. More than 100,000 sites are using this plugin, and the dangerous part is how little access an attacker needs. A normal student account can be enough.

The vulnerability allows malicious data to be passed into PHP, and under the right conditions that can become remote code execution. In other words, a student account could potentially become control of the server.

The vulnerability was fixed in version 4.0.8 and the current release is 4.0.9. So, if you run Tutor LMS, update it to the latest version. And if your site allows open student registration, don’t put this one off.

Next up, Popup Maker, and this one has scale. Popup Maker is installed on more than 700,000 WordPress sites, and a new vulnerability was published yesterday. An attacker doesn’t need a WordPress account.

They can inject malicious JavaScript into data handled by the plugin. That code can later execute inside the browser of another user, including someone working inside WordPress admin.

The affected versions go up to 1.24.0, and the fix is version 1.25.0. So, if you use Popup Maker, update it to 1.25.0.

This is a good example of why stored attacks matter. The attacker doesn’t have to be there when the code finally runs. They plant it and wait.

Next up, Booking Calendar. It has a privilege escalation problem, and the plugin has around 40,000 active installations. This one does require an existing WordPress account, but an editor-level user can potentially turn themselves into an administrator.

The flaw lets them change core settings. That includes turning on registration and setting the default role for new users to administrator. They can then simply register a new admin account.

The fix is in version 11.8.3. The developer says that release locks the request down to legitimate Booking Calendar settings. So, if you use Booking Calendar, update to 11.8.3 or later.

And remember, an editor account isn’t supposed to control WordPress itself. When a plugin lets it do that, you’ve crossed a very important security boundary.

And finally this morning, one vulnerability affecting several different cloud plugins. These are the WP Cloud Plugins for Google Drive, Dropbox, OneDrive, SharePoint and Box. Together, the developer says the product family has more than 25,000 customers.

The vulnerability affects versions up to 3.8.3. A normal subscriber-level user can potentially upload a dangerous file through the plugin’s import system. The file type isn’t checked properly, so that upload could include an executable PHP file, and that can lead to remote code execution.

The patch line begins with version 3.9.0. So, if you use any of those WP Cloud Plugins, make sure you’re on 3.9.0 or later.

The important lesson here is that cloud integration plugins often have permissions to move files. The moment a plugin can write files to your server, file validation becomes a security boundary.

And that’s your WordPress security briefing for today. The big one this morning is The Events Calendar: 600,000 sites, no login required, and potential remote code execution.

Then check your inventory for Tutor LMS, Popup Maker, Booking Calendar and the WP Cloud Plugins. Patch what you actually run, and check the sites that were exposed.