CVE-2026-11349
Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_load_more
CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th
The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection vulnerability that allows attackers to extract sensitive data from the database.
| Vendor | unknown |
| Product | modern event calendar pro |
| Published | Jul 20, 2026 |
| Last Updated | Jul 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown modern event calendar pro
Be the first to know when new high vulnerabilities affecting unknown modern event calendar pro are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Modern Event Calendar Pro
0 < 7.34.0
Unknown / Modern Events Calendar Lite
0 < 7.34.0
References
Credits
Anthony Cihan WPScan