Plugin Used by 150,000 WordPress Sites Targeted in Cyber Attacks
A calendar plugin for WordPress, used by 150,000 websites, is being used to upload random files.

According to Wordfence, cybercriminals are exploiting a security vulnerability in the Modern Events Calendar plugin for WordPress, which is present on over 150,000 websites.
The plugin was developed by Webnus and is used to organize and manage hybrid, virtual, and physical events. The vulnerability (CVE-2024-5441) has a criticality score of 8.8 and is being used in attacks.
The vulnerability stems from the lack of file type validation in the 'set_featured_image' function, which is used by plugins to upload and set images for events. The vulnerability allows for random file uploads and remote code execution.
Source: Plugin used by 150,000 WordPress sites targeted by cyberattacks (itsecurity.pt)