Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Modern Events Calendar Lite — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in Modern Events Calendar Lite, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive vulnerability aggregation report for Modern Events Calendar Lite, focusing on WordPress plugin security weaknesses tagged under the vendor category. It serves as a centralized resource for security researchers, developers, and site administrators seeking detailed insights into the specific security flaws affecting this popular event management tool. The collection aggregates diverse vulnerability types, including Cross-Site Scripting (XSS), SQL Injection, and Broken Access Control issues that have been publicly disclosed or identified in recent security audits. The data covers a broad historical time range, tracking incidents from early plugin versions up to the most recent updates, ensuring that users can review the complete lifecycle of security risks associated with this software. By compiling these entries, the page offers a chronological view of how weaknesses have emerged and been addressed over time. Here, you can track a vendor's advisories to understand how quickly patches are deployed when new threats arise. You can also understand a weakness class by examining specific instances within this product, seeing how generic vulnerabilities manifest in real-world scenarios. Additionally, you can look up a product's vulnerability history to assess the overall security posture and maintenance quality of Modern Events Calendar Lite. This information is critical for making informed decisions about whether to continue using the plugin or to seek alternatives with stronger security records. The aggregated data helps highlight patterns in code quality and response times, providing a clearer picture of the risks involved in relying on this specific open-source solution for managing events on WordPress sites.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2021-4458 Modern Events Calendar Lite <= 6.3.0 - Unauthenticated SQL Injection CWE-89 5.9 Medium2025-07-12
CVE-2025-5733 Modern Events Calendar <= 7.21.9 - Information Exposure CWE-201 5.3 Medium2025-06-06
CVE-2023-4021 Modern Events Calendar lite < 7.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting CWE-79 4.4 Medium2023-10-20
CVE-2023-1400 Modern Events Calendar lite < 6.5.2 - Admin+ Stored XSS 4.8 -2023-03-27
CVE-2022-30533 Modern Events Calendar Lite 跨站脚本漏洞 5.4 -2022-06-16
CVE-2022-0364 Modern Events Calendar Lite < 6.4.0 - Contributor+ Stored Cross Site Scripting CWE-79 5.4 -2022-03-21
CVE-2021-25046 Modern Events Calendar Lite < 6.2.0 - Subscriber+ Category Add Leading to Stored XSS CWE-79 5.4 -2022-01-17
CVE-2021-24946 Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injection CWE-89 9.8 -2021-12-13
CVE-2021-24925 Modern Events Calendar Lite < 6.1.5 - Reflected Cross-Site Scripting CWE-79 6.1 -2021-12-13
CVE-2021-24716 Modern Events Calendar Lite < 5.22.3 - Authenticated Stored Cross Site Scripting CWE-79 5.4 -2021-11-01
CVE-2021-24687 Modern Events Calendar Lite < 5.22.2 - Admin+ Stored Cross-Site Scripting CWE-79 4.8 -2021-10-04
CVE-2021-24145 Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE CWE-434 7.2 -2021-03-18
CVE-2021-24146 Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export CWE-284--2021-03-18
CVE-2021-24147 Modern Events Calendar Lite < 5.16.5 - Authenticated Stored Cross-Site Scripting (XSS) CWE-79 5.4 -2021-03-18
CVE-2021-24149 Modern Events Calendar Lite < 5.16.6 - Authenticated SQL Injection CWE-89 8.8 -2021-03-18

All 15 known CVE vulnerabilities affecting Modern Events Calendar Lite with full Chinese analysis, references, and POCs where available.