๐Ÿ” CVE Alert

CVE-2026-11349

HIGH 8.6

Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_load_more

CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th

The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection vulnerability that allows attackers to extract sensitive data from the database.

Vendor unknown
Product modern event calendar pro
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for unknown modern event calendar pro

Be the first to know when new high vulnerabilities affecting unknown modern event calendar pro are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Modern Event Calendar Pro
0 < 7.34.0
Unknown / Modern Events Calendar Lite
0 < 7.34.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/572229cb-8a09-406d-8623-7d6b553bfdde/

Credits

Anthony Cihan WPScan