Executive brief
The Modern Events Calendar plugins for WordPress, which are used to manage and display event schedules, contain a security flaw that allows unauthorized individuals to access the website's database. By exploiting this vulnerability, an attacker could steal sensitive information, including user details or site configuration data, without needing a login. This could lead to a full site compromise or data breach.
Technical details
An unauthenticated SQL injection vulnerability exists in the Modern Events Calendar (Lite and Pro) plugins before version 7.34.0. The flaw is located within the 'mec_list_load_more' AJAX action, which fails to properly sanitize and escape a request parameter before incorporating it into a SQL statement. Because this AJAX action is available to unauthenticated users, a remote attacker can send specially crafted requests to execute arbitrary SQL commands. This allows for the extraction of sensitive information from the WordPress database, such as user credentials, session tokens, and site metadata. The issue is resolved in version 7.34.0.
Affected products
- Webnus Modern Event Calendar Pro < 7.34.0
- Webnus Modern Events Calendar Lite < 7.34.0
Timeline
- 2026-06-29: disclosed
- 2026-07-20: advisory