WooCommerce CVE-2026-48888: Update to 11.1.0 Now
If your business runs WooCommerce, a high-severity vulnerability is sitting in your store right now unless you have already updated to version 11.1.0. An
Over 600,000 websites running The Events Calendar plugin are currently exposed to a pair of vulnerabilities that allow an anonymous attacker to take
Over 600,000 websites running The Events Calendar plugin are currently exposed to a pair of vulnerabilities that allow an anonymous attacker to take complete control of a WordPress site without logging in, without an account, and without any interaction from the site owner. Discovered in August 2026 and assigned a CVSS score of 9.8, these flaws sit at the top end of the severity scale — a score reserved for vulnerabilities where the attacker faces almost no barrier and the potential damage is total. Think of it as leaving the front door, the back door, and every window open simultaneously.
The attack vector is the comment preview feature built into event pages. When a visitor submits a comment on an event, the plugin processes a preview of that comment before it is approved or published. The flaw means an attacker can embed malicious code inside that preview request, and the server will execute it. The comment never needs to go live or pass moderation. If comments are enabled on your event pages, the attack can be triggered the moment the request hits your server.
A successful exploit gives an attacker the same level of access as a server administrator. From that position, they can extract every customer record stored in your database — names, email addresses, purchase history, and any payment data your site retains. They can install malware that redirects your visitors to phishing pages, turning your site into a tool against the very customers you are trying to serve, or plant backdoors for future access and use your server to attack other websites, leaving your IP address in the logs.
For any business handling personal data from UK or EU customers, a breach of this kind triggers GDPR notification obligations. The Information Commissioner’s Office requires notification within 72 hours of becoming aware of a breach that poses a risk to individuals. Failure to notify carries fines of up to £17.5 million or 4% of annual global turnover, whichever is higher. The reputational damage of customers discovering their data was stolen through a plugin you did not update is a separate cost, and one that is harder to quantify than any regulatory fine.
Three compounding factors produce that 9.8 score: the attack requires no authentication, it can be executed remotely over the internet, and it requires no interaction from a legitimate user on the site. Most serious vulnerabilities require at least one of those conditions to be absent. This one has none of them.
The specific mechanism matters because it changes how you assess your own exposure. Disabling public registration or keeping your site behind a login wall offers no protection here. The comment preview endpoint is accessible to anyone who can reach your site, meaning even a site that has never had a single registered user can be exploited if event page comments are enabled.
Version 6.17.4.1 of The Events Calendar plugin patches both vulnerabilities. If your site is running any earlier version and has event pages with comments enabled, updating immediately is the single most important thing you can do right now. Log into your WordPress dashboard, go to Plugins, find The Events Calendar, and update it. If you have automatic updates enabled for plugins, verify that the update has actually applied rather than assuming it has.
After updating, review your comment settings. In WordPress, comment permissions can be set globally under Settings and then Discussion, but they can also be overridden at the individual post or event level. A site owner who disabled comments globally years ago may still have event pages with comments enabled if those pages were created before the global setting was changed, or if the plugin applied its own defaults, which means checking each event page individually is the only way to be certain.
One consequence that tends to go unexamined: if your site is compromised and search engines index malware or phishing content served from your domain, Google will flag the entire domain as dangerous. Visitors using Chrome will see a full-page warning before they reach you. Recovering from that flag requires cleaning the site, submitting a review request through Google Search Console, and waiting for Google to re-crawl and reassess — a process that takes days at minimum and sometimes weeks, during which organic search traffic effectively stops. For a business that depends on its website to generate enquiries or sales, that is a direct revenue impact with no ceiling.
If you are running The Events Calendar plugin and you are not certain which version is installed, or you are not confident in your ability to audit comment settings across every event page on the site, I can carry out a targeted security audit for you. I will check the plugin version, review comment configurations across all event pages, scan for signs of existing compromise, and confirm your site is not already carrying a backdoor from an earlier attack. These vulnerabilities were disclosed in August 2026, and active exploitation typically follows public disclosure within days, so the window for acting before attackers have had time to scan and target vulnerable installations is closing. Contact The WordPress Guy to arrange the audit now.
Related articles
If your business runs WooCommerce, a high-severity vulnerability is sitting in your store right now unless you have already updated to version 11.1.0. An
If your business uses WordPress, there is a reasonable chance your site is running the All-in-One WP Migration and Backup plugin. With over five million
A vulnerability in WooCommerce allows an attacker to escalate their privileges on your site. Any store running a version below 11.0 is exposed: a user
Security issues need permanent fixes, not surface-level patches. This is exactly the work I specialise in.
View security services →
Jason Boyd
Specialist WordPress Engineer · Former W3C Invited Expert · 20+ years
I fix the WordPress problems other developers walk away from. Backed by a 1st Class degree in Computer Science, an MSc in Cybersecurity, and over 20 years of specialist WordPress work, I diagnose issues at their root cause and resolve them permanently, for businesses that cannot afford guesswork or repeat failures.
If this article describes your situation, I can diagnose the specifics and fix it properly. Send your brief and I'll respond the same working day.