Modern Event Calendar WordPress Plugins Unauthenticated SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in the Modern Event Calendar Pro and Modern Events Calendar Lite WordPress plugins, both prior to version 7.34.0. The vulnerability arises because the plugins do not properly sanitize and escape a request parameter before incorporating it into a SQL statement. This issue is accessible through an AJAX action available to unauthenticated users, allowing attackers to exploit the vulnerability and extract sensitive data from the database.

Impact

Exploitation of this vulnerability allows for unauthenticated SQL injection, enabling attackers to manipulate SQL queries and potentially extract sensitive data from the database.

Remediation

Users are advised to update to Modern Event Calendar Pro or Modern Events Calendar Lite version 7.34.0 or later.

Added: Jul 20, 2026, 7:32 AM
Updated: Jul 20, 2026, 7:32 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
3.1
exploitability
9.7
remediation
7.7
relevance
10.0
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.