Benin’s bjCSIRT issued a warning about remote code execution affecting the WordPress plugin The Events Calendar. A related Patchstack vulnerability entry identifies PHP object injection associated with plugin version 6.17.4. PHP object injection can potentially enable code execution when exploitable object-handling paths and suitable application components are present; the available information does not establish those prerequisites or confirm active exploitation.
Organizations using The Events Calendar should prioritize identifying installed versions, checking the affected-version range and remediation guidance in the Patchstack entry and vendor advisories, and applying a confirmed security update. If no fix is available, assess temporarily disabling the plugin, particularly on business-critical or internet-facing WordPress sites. Do not assume version 6.17.4 is a fixed release merely because it appears in the vulnerability listing.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
bjCSIRT published an advisory about a remote code execution vulnerability affecting The Events Calendar plugin for WordPress. The supplied reference does not provide technical details or remediation information.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.