Modern Events Calendar Lite < 6.4.0 - Contributor+ Stored Cross Site Scripting
Description
The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Modern Events Calendar Lite <6.4.0 fails to sanitize Hourly Schedule parameters, allowing contributors to inject stored XSS.
Vulnerability
The Modern Events Calendar Lite plugin for WordPress versions before 6.4.0 does not properly sanitize and escape some of the Hourly Schedule parameters. This allows users with a role as low as contributor to perform Stored Cross-Site Scripting (XSS) attacks. The affected versions are all prior to 6.4.0. [1]
Exploitation
An attacker with a contributor-level account (or higher) can craft a malicious payload in the Hourly Schedule fields when creating or editing an event. The plugin fails to sanitize and escape these inputs, so the payload is stored in the database and later executed in the browsers of users viewing the event, such as administrators or other site visitors. [1]
Impact
Successful exploitation leads to stored XSS, which can result in arbitrary JavaScript execution in the context of the victim's session. An attacker could potentially steal cookies, session tokens, or perform actions on behalf of the victim, such as creating new admin users or defacing the site.
Mitigation
The vulnerability is fixed in version 6.4.0 of the Modern Events Calendar Lite plugin. Users are advised to update to this version or later. As of the publication date, no workaround is provided, but updating is the recommended mitigation. [1]
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/0eb40cd5-838e-4b53-994d-22cf7c8a6c50mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.