Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_load_more
Vulnerability Description
The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection vulnerability that allows attackers to extract sensitive data from the database.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress Modern Events Calendar Lite SQL注入漏洞
Vulnerability Description
WordPress Modern Events Calendar Lite是WordPress基金会的一款事件日历管理插件。 WordPress Modern Events Calendar Lite 7.34.0之前版本存在SQL注入漏洞,该漏洞源于未对请求参数进行清理和转义,直接用于SQL语句,且通过未认证用户可访问的AJAX动作触发,可能导致未认证的SQL注入攻击,允许攻击者从数据库中提取敏感数据。
CVSS Information
N/A
Vulnerability Type
N/A