A plugin called “Events Calendar Pro” for the website platform WordPress has a security vulnerability that allows attackers to inject harmful code and potentially execute it from a remote location. This flaw affects all versions up to 7.0.2 and can be exploited by users with administrator-level access or higher. Even lower level users may be able to exploit this vulnerability if the plugin is installed with a page builder called Elementor.