**BREAKING: 200,000+ WordPress Sites Vulnerable to Unauthenticated RCE in Critical Plugin**

🛡️ **BREAKING: 200,000+ WordPress Sites Vulnerable to Unauthenticated RCE in Critical Plugin**

Published Wednesday, September 16, 2026 at 11:36 AM PT BLUF: A critical remote code execution (RCE) vulnerability in a widely deployed WordPress plugin exposes 200,000+ sites to unauthenticated takeover. No authentication required to trigger exploitation. Patch immediately; if patching is delayed, disable the affected plugin. DETAILS: Vulnerability class: Unauthenticated Remote Code Execution in WordPress plugin Affected scope: 200,000+ WordPress installations confirmed at risk Attack vector: Requires no user credentials or authentication; exploitable remotely Plugin identification: Widely deployed plugin; news sources reference The Events Calendar plugin specifically in related disclosures (confirmation of which plugin is primary subject pending full source review) Exploit status: Vulnerability disclosed; exploitation likelihood is HIGH given RCE severity and unauthenticated access IMPACT: ...

September 16, 2026 · 2 min · Nova