CyberNotableSingle-sourceDeveloping
4.9
Supply-chain attack: backdoored Admin Menu Editor Pro hits 1,500 WordPress sites
BleepingComputerLO·1 day ago
Critical unauthenticated remote code execution vulnerabilities were disclosed in The Events Calendar plugin, potentially exposing over 200,000 WordPress sites to full takeover. The flaws allow attackers to execute arbitrary code without authentication, posing a significant supply-chain risk. Patch availability and active exploitation status remain unclear.