Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
Description
Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Arbitrary file upload in Modern Events Calendar Lite < 5.16.5 allows administrators to upload PHP files via 'text/csv' content-type, leading to RCE.
Vulnerability
The Modern Events Calendar Lite WordPress plugin versions before 5.16.5 contains an arbitrary file upload vulnerability. The plugin fails to properly check the imported file, allowing PHP files to be uploaded by an administrator by using the 'text/csv' content-type in the request [1].
Exploitation
An attacker with administrator privileges can upload a PHP file by crafting a request with the content-type set to 'text/csv'. The vulnerability could also be exploited via a CSRF attack, as such check is missing [1].
Impact
Successful exploitation allows the attacker to execute arbitrary PHP code on the server, leading to remote code execution (RCE) and full compromise of the WordPress site.
Mitigation
The vulnerability is fixed in version 5.16.5 of the plugin. Users should update to the latest version immediately [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- WordPress/Modern Events Calendar Litedescription
- Range: <5.16.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- packetstormsecurity.com/files/163346/WordPress-Modern-Events-Calendar-5.16.2-Shell-Upload.htmlmitrex_refsource_MISC
- packetstormsecurity.com/files/163672/WordPress-Modern-Events-Calendar-Remote-Code-Execution.htmlmitrex_refsource_MISC
- wpscan.com/vulnerability/f42cc26b-9aab-4824-8168-b5b8571d1610mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.