
Critical WordPress Plugin Bugs Let Attackers Reset Admin Passwords and Take Over Sites
Two critical, unauthenticated vulnerability chains in The Events Calendar WordPress plugin could let remote attackers reset administrator passwords, execute operating-system commands, and take over vulnerable websites. The vulnerabilities affect The Events Calendar, a widely used WordPress plugin installed on more than 600,000 sites. StellarWP, the plugin’s developer, has released fixes, and administrators are urged to […]
The post Critical WordPress Plugin Bugs Let Attackers Reset Admin Passwords and Take Over Sites appeared first on Cyber Security News.