Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Modern Events Calendar Lite CRITICAL 9.8
CVE-2021-4458

The Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_ajax_mec_load_single_page' AJAX…

Fix: 6.4.0+
Fix from $2,300 2025-07-12
Modern Events Calendar CRITICAL 9.6
CVE-2024-6522

The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'me…

Fix: 7.13.0+
Fix from $2,300 2024-08-07
Modern Events Calendar Lite HIGH 8.8
CVE-2024-5441

The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image…

Fix: 7.12.0+
Fix from $1,950 2024-07-09
Modern Events Calendar Lite MEDIUM 5.4
CVE-2022-30533

Cross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject an arbitr…

Fix: 6.3.0+
Fix from $1,600 2022-06-16
Modern Events Calendar Lite MEDIUM 5.4
CVE-2022-0364EPSS 70%

The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow u…

Fix: 6.4.0+
Fix from $1,600 2022-03-21
Modern Events Calendar Lite MEDIUM 5.4
CVE-2021-25046

The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters …

Fix: 6.2.0+
Fix from $1,600 2022-01-17
Modern Events Calendar Lite CRITICAL 9.8
CVE-2021-24946EPSS 73%

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in t…

Fix: 6.1.5+
Fix from $2,300 2021-12-13
Modern Events Calendar Lite MEDIUM 6.1
CVE-2021-24925

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_m…

Fix: 6.1.5+
Fix from $1,600 2021-12-13
Modern Events Calendar Lite MEDIUM 5.4
CVE-2021-24716

The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users with access to adjust setting…

Fix: 5.22.3+
Fix from $1,600 2021-11-01
Modern Events Calendar Lite HIGH 8.8
CVE-2021-24149

Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in th…

Fix: 5.16.6+
Fix from $1,950 2021-03-18
Modern Events Calendar Lite HIGH 7.5
CVE-2021-24146EPSS 31%

Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the exp…

Fix: 5.16.5+
Fix from $1,950 2021-03-18
Modern Events Calendar Lite HIGH 7.2
CVE-2021-24145EPSS 88%

Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing…

Fix: 5.16.5+
Fix from $1,950 2021-03-18
Modern Events Calendar Lite MEDIUM 5.4
CVE-2021-24147

Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not sanitise the mic_c…

Fix: 5.16.5+
Fix from $1,600 2021-03-18
Modern Events Calendar Lite MEDIUM 5.4
CVE-2020-9459

Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1.6 for WordPress allows remote…

Fix: after 5.1.6
Fix from $1,600 2020-02-28