VYPR
Unrated severityNVD Advisory· Published Mar 21, 2022· Updated Aug 2, 2024

Modern Events Calendar Lite < 6.4.0 - Contributor+ Stored Cross Site Scripting

CVE-2022-0364

Description

The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Modern Events Calendar Lite <6.4.0 fails to sanitize Hourly Schedule parameters, allowing contributors to inject stored XSS.

Vulnerability

The Modern Events Calendar Lite plugin for WordPress versions before 6.4.0 does not properly sanitize and escape some of the Hourly Schedule parameters. This allows users with a role as low as contributor to perform Stored Cross-Site Scripting (XSS) attacks. The affected versions are all prior to 6.4.0. [1]

Exploitation

An attacker with a contributor-level account (or higher) can craft a malicious payload in the Hourly Schedule fields when creating or editing an event. The plugin fails to sanitize and escape these inputs, so the payload is stored in the database and later executed in the browsers of users viewing the event, such as administrators or other site visitors. [1]

Impact

Successful exploitation leads to stored XSS, which can result in arbitrary JavaScript execution in the context of the victim's session. An attacker could potentially steal cookies, session tokens, or perform actions on behalf of the victim, such as creating new admin users or defacing the site.

Mitigation

The vulnerability is fixed in version 6.4.0 of the Modern Events Calendar Lite plugin. Users are advised to update to this version or later. As of the publication date, no workaround is provided, but updating is the recommended mitigation. [1]

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.