Modern Event Calendar Pro
cpe:2.3:a:webnus:modern_events_calendar:*:*:*:*:wordpress:*:*
- < 7.34.0
A SQL injection vulnerability has been identified in the Modern Event Calendar Pro and Modern Events Calendar Lite WordPress plugins, both prior to version 7.34.0. The vulnerability arises because the plugins do not properly sanitize and escape a request parameter before incorporating it into a SQL statement. This issue is accessible through an AJAX action available to unauthenticated users, allowing attackers to exploit the vulnerability and extract sensitive data from the database.
Exploitation of this vulnerability allows for unauthenticated SQL injection, enabling attackers to manipulate SQL queries and potentially extract sensitive data from the database.
Users are advised to update to Modern Event Calendar Pro or Modern Events Calendar Lite version 7.34.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.