WORDPRESS SECURITY
600,000+ sites are exposed after September 2026's critical plugin flaws.
STEP 1
Two critical bugs in The Events Calendar hit versions up to 6.17.4 — update to 6.17.4.1 or later now.
STEP 2
Both flaws trigger through unauthenticated comments, so disabling them blocks the attack path instantly.
STEP 3
Check each active plugin's changelog this week — attackers scan for unpatched CVSS 9.8 bugs within days.
STEP 4
Wordfence and most host firewalls already block known exploit patterns for these flaws — enable one.
STEP 5
Look for unfamiliar admin users, unknown files, or spam pages — the tell-tale signs of a takeover.