Impact
A flaw in the Modern Event Calendar Pro and Lite WordPress plugins before version 7.34.0 allows an attacker to supply a malicious value to the mec_list_load_more AJAX endpoint. The plugin fails to sanitise or escape the input before incorporating it into a SQL query, enabling an unauthenticated SQL injection that can read arbitrary database tables, exposing sensitive information such as user credentials, event data, or site configuration.
Affected Systems
The vulnerability affects the Modern Events Calendar Pro and Modern Events Calendar Lite WordPress plugins, any installation running a version older than 7.34.0. All WordPress sites with these plugins deployed are potentially impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity, but the EPSS score of less than 1% suggests that the likelihood of exploitation at this time is currently low. The flaw is not listed in the CISA KEV catalog, meaning no confirmed public exploit is known. The attack vector is a local unauthenticated AJAX request, requiring no user interaction beyond sending a crafted request to the affected endpoint.
OpenCVE Enrichment