Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 31%
from disclosure to weapon106 days
Published on NVDMar 18
1st PoC+106d
exploitation probability
31%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.
Affected products
Unknown · Modern Events Calendar Litepublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/50084unverifiedcve_referencepacketstormsecurity.com/files/163345/WordPress-Modern-Events-Calendar-5.16.2-Information-Disclosure.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.