Back to overview

CVE-2026-11349

HIGH Exploitation: PoC
8.6
CVSS 3.1
Description
The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection vulnerability that allows attackers to extract sensitive data from the database.

Metadata

CVE ID
CVE-2026-11349
State
PUBLISHED
Assigner
WPScan
Reserved
2026-06-05 09:13 UTC
Published
2026-07-20 06:00 UTC
Last updated
2026-07-20 13:16 UTC
Primary CWE
CWE-89
CWE-89 Improper Neutralization of Special Elements used in a…
Vendor / Product
Unknown / Modern Event Calendar Pro
Sources
cve.org  ·  NVD

Severity & Metrics

8.6 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
partial
Affected products (2)
VendorProductPlatformVersions
Unknown Modern Event Calendar Pro 0 < 7.34.0
Unknown Modern Events Calendar Lite 0 < 7.34.0
Weakness (CWE)
CWESourceDescription
cna CWE-89 SQL Injection
CWE-89 adp CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.6 HIGH 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Back to overview