This popular WordPress calendar plugin is being targeted by hackers, so act now



If your WordPress website is running the Modern Events Calendar plugin, make sure to update immediately, since it carries a high-severity vulnerability that can be abused for full website takeover. To make matters worse, researchers are saying that hackers are already abusing the flaw in the wild.

Cybersecurity researcher Friderika Baranyai first discovered the issue in late May 2024 during the Wordfence Bug Bounty Extravaganza. It is described as a missing file type validation bug, now tracked as CVE-2024-5441. It carries a severity score of 8.8 (high). 

https://cdn.mos.cms.futurecdn.net/4dB7zyRNSR7f8BCMoB3JqQ-1200-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img