The PHP Event Calendar plugin for WordPress is vulnerable to an issue that could allow unauthenticated attackers to upload malicious files to the affected website’s server. This issue affects versions up to and including 1.5. With this vulnerability, attackers may be able to execute code remotely. To protect against this, users should update to the latest version of the PHP Event Calendar plugin for WordPress.