Description
The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 7.21.9. This is due improper or insufficient validation of the id property when exporting calendars. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
Published: 2025-06-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The Modern Events Calendar Lite plugin for WordPress contains a full path disclosure flaw that is triggered during the export of a calendar. This occurs because the plugin does not properly validate the id parameter. The weakness is classified as CWE-201 (Information Exposure) due to insufficient validation of the ID parameter when exporting calendars. An unauthenticated attacker can trigger the export endpoint and obtain the absolute file system path of the WordPress installation. The disclosed data alone is not immediately sensitive but can facilitate reconnaissance or the planning of further attacks.

Affected Systems

The vulnerability affects all releases of the Modern Events Calendar Lite plugin distributed by webnus that are version 7.21.9 or earlier. These versions are available to WordPress sites that use the plugin.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests that exploitation in the wild is unlikely. The vulnerability is not listed in the CISA KEV catalog. Because the path disclosure can be obtained without authentication, an attacker can easily obtain the information, but this alone does not enable a direct compromise. It may, however, aid subsequent attacks if another vulnerability is present.

Generated by OpenCVE AI on April 22, 2026 at 07:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Modern Events Calendar Lite plugin to the latest version (above 7.21.9) to fix the CWE-201 information exposure flaw.
  • Restrict the calendar export functionality to authenticated administrators only to mitigate the CWE-201 vulnerability until a patch is applied.
  • If a patch or configuration change cannot be applied immediately, disable the calendar export endpoint to prevent path disclosure caused by the CWE-201 flaw.

Generated by OpenCVE AI on April 22, 2026 at 07:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17050 The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 7.21.9. This is due improper or insufficient validation of the id property when exporting calendars. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
History

Fri, 06 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 04:00:00 +0000

Type Values Removed Values Added
Description The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 7.21.9. This is due improper or insufficient validation of the id property when exporting calendars. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
Title Modern Events Calendar <= 7.21.9 - Information Exposure
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Webnus Modern Events Calendar Lite
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:29:47.838Z

Reserved: 2025-06-05T15:04:36.173Z

Link: CVE-2025-5733

cve-icon Vulnrichment

Updated: 2025-06-06T15:44:14.809Z

cve-icon NVD

Status : Deferred

Published: 2025-06-06T04:16:01.840

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-5733

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T07:45:11Z

Weaknesses