CVE-2026-73339
- EPSS 0.38%
- Veröffentlicht 18.08.2026 14:00:06
- Zuletzt bearbeitet 20.08.2026 12:48:31
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
CVE-2026-32583
- EPSS 0.7%
- Veröffentlicht 16.03.2026 15:11:29
- Zuletzt bearbeitet 22.04.2026 21:32:08
Missing Authorization vulnerability in Webnus Inc. Modern Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Modern Events Calendar: from n/a through 7.29.0.
CVE-2024-6522
- EPSS 0.41%
- Veröffentlicht 07.08.2024 11:15:45
- Zuletzt bearbeitet 01.03.2025 01:20:09
The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'mec_fes_form' AJAX function. This makes it possible for authenticated attackers, with Subscriber-level ...
CVE-2024-5441
- EPSS 1.12%
- Veröffentlicht 09.07.2024 06:15:02
- Zuletzt bearbeitet 08.04.2026 17:19:03
The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image function in all versions up to, and including, 7.11.0. This makes it possible for authenticated atta...