Modern Events Calendar <= 7.21.9 - Information Exposure

CVE Details

Basic Information

Title Modern Events Calendar <= 7.21.9 - Information Exposure
Type cve
Published 2025-06-06T03:41:23.431Z
Last Seen

Product Information

Vendor webnus/
Product Modern Events Calendar Lite
Version *

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure. Unauthenticated attackers can retrieve the full path of the web application, which can aid other attacks. The information is not useful on its own and requires another vulnerability to be present for damage.
AI Severity Medium
Vendor Webnus
Product Modern Events Calendar Lite
Affected Version <= 7.21.9

Affected Products

  • webnus/ Modern Events Calendar Lite *

Additional Information

CVE List
CWE List CWE-201
Bulletin Family

Description

The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 7.21.9. This is due improper or insufficient validation of the id property when exporting calendars. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.