Vulnerability record · CVE-2022-0364 · published 21 March 2022
CVE-2022-0364: Modern Events Calendar Lite stored XSS via Hourly Schedule parameters
Webnus · Modern Events Calendar Lite
The Modern Events Calendar Lite WordPress plugin before 6.4.0 fails to sanitize and escape some Hourly Schedule parameters, allowing stored cross-site scripting. Because the payload persists in stored content, it can execute in the browser of any user who later views the affected schedule, including higher-privileged users.
Description
The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS is medium (5.4) and exploitation requires contributor access plus victim interaction, but public exploit detail and a very high EPSS score raise the practical risk.
What it is
The Modern Events Calendar Lite WordPress plugin before 6.4.0 fails to sanitize and escape some Hourly Schedule parameters, allowing stored cross-site scripting. Because the payload persists in stored content, it can execute in the browser of any user who later views the affected schedule, including higher-privileged users.
Impact
An attacker with contributor-level access can inject script that runs in the context of other users' sessions, enabling session theft, credential capture, or actions performed as the victim.
Attack surface
Reached over the network through the WordPress plugin's Hourly Schedule functionality; the attacker needs an authenticated account with at least contributor role, and exploitation requires a victim to view the injected content (UI:R).
Exploitation
Not listed in CISA KEV, but EPSS is high (0.69552, 99.3rd percentile) and the WPScan references are tagged Exploit, indicating public exploit detail exists.
What to do
- Update Modern Events Calendar Lite to version 6.4.0 or later.
- If immediate patching is not possible, restrict contributor and similar low-privilege roles, or disable the plugin until it can be updated.
- Apply input sanitization and output escaping to Hourly Schedule fields as a compensating control if code changes are feasible.
- Review and remove any stored Hourly Schedule content containing script or unexpected HTML.
- Enforce least privilege on WordPress accounts and audit role assignments.
Detection
- Search event and schedule content in the database for script tags or suspicious HTML in Hourly Schedule fields.
- Monitor web server and WordPress logs for requests to plugin endpoints containing encoded script payloads.
- Alert on new or modified schedule entries created by contributor-level accounts.
- Review WAF or application logs for XSS patterns targeting the plugin's schedule parameters.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://wpscan.com/vulnerability/0eb40cd5-838e-4b53-994d-22cf7c8a6c50 | ExploitThird Party Advisory |
| https://wpscan.com/vulnerability/0eb40cd5-838e-4b53-994d-22cf7c8a6c50 | ExploitThird Party Advisory |
Track CVE-2022-0364 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-0364), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.