Critical RCE Vulnerabilities in WordPress 'The Events Calendar' Plugin Threaten Over 200,000 Sites
Two critical vulnerabilities, CVE-2023-31145 and CVE-2023-31146, in the popular WordPress plugin 'The Events Calendar' allow unauthenticated attackers to execute arbitrary code, potentially leading to website takeover for over 200,000 sites.

Two critical vulnerabilities have been discovered in The Events Calendar, a widely-used WordPress plugin that enhances website functionality with event management features. These flaws, identified as CVE-2023-31145 and CVE-2023-31146, pose a significant risk to the security of over 200,000 websites that rely on the plugin.
The vulnerabilities allow unauthenticated attackers to achieve remote code execution (RCE) on affected WordPress sites. This means that an attacker does not need any prior access or login credentials to exploit these flaws. The ease of exploitation, combined with the plugin's extensive user base, creates a high-risk scenario for website owners.
Details surrounding the exact technical mechanism of the exploits are still emerging, but the implications are severe. Successful exploitation could grant attackers full control over a compromised website. This level of access enables a wide range of malicious activities, including defacing websites, injecting malicious content or malware, stealing sensitive user data, and using the compromised site to launch further attacks.
Given that The Events Calendar is installed on more than 200,000 websites, the potential attack surface is substantial. Attackers could automate the scanning for and exploitation of vulnerable sites, leading to widespread compromise. The plugin's popularity makes it an attractive target for threat actors seeking to gain a foothold on numerous websites quickly.
While the specific details of the vulnerabilities are being closely examined, the discovery highlights the ongoing security challenges within the vast WordPress ecosystem. Plugins, while adding valuable functionality, can also introduce significant security risks if not properly developed and maintained.
Users of The Events Calendar are strongly advised to update to the latest version of the plugin as soon as possible. Security researchers and vendors are working to provide detailed guidance and patches, but proactive updating remains the most effective defense against these types of threats. Website administrators should also ensure their WordPress core and other plugins are kept up-to-date to maintain a robust security posture.
The disclosure of these critical RCE vulnerabilities serves as a stark reminder of the importance of regular security audits and prompt patching for all website components. The potential for unauthenticated takeover of a large number of sites underscores the need for continuous vigilance in the cybersecurity landscape.