CVE-2026-11349
Unknown Modern Event Calendar Pro, Modern Events Calendar Lite 취약점
The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection vulnerability that allows attackers to extract sensitive data from the database.
- 대응 우선순위
- 점검
- CVSS
- 8.6
- EPSS
- 0.32% 백분위 24.6% · 2026.08.03 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.07.20