← Vulnerability feed

Vulnerability record · CVE-2022-0364 · published 21 March 2022

CVE-2022-0364: Modern Events Calendar Lite stored XSS via Hourly Schedule parameters

Webnus · Modern Events Calendar Lite

The Modern Events Calendar Lite WordPress plugin before 6.4.0 fails to sanitize and escape some Hourly Schedule parameters, allowing stored cross-site scripting. Because the payload persists in stored content, it can execute in the browser of any user who later views the affected schedule, including higher-privileged users.

5.4 CVSS 3.1 Medium EPSS 70% · top 0.7% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityCVSS is medium (5.4) and exploitation requires contributor access plus victim interaction, but public exploit detail and a very high EPSS score raise the practical risk.

What it is

The Modern Events Calendar Lite WordPress plugin before 6.4.0 fails to sanitize and escape some Hourly Schedule parameters, allowing stored cross-site scripting. Because the payload persists in stored content, it can execute in the browser of any user who later views the affected schedule, including higher-privileged users.

Impact

An attacker with contributor-level access can inject script that runs in the context of other users' sessions, enabling session theft, credential capture, or actions performed as the victim.

Attack surface

Reached over the network through the WordPress plugin's Hourly Schedule functionality; the attacker needs an authenticated account with at least contributor role, and exploitation requires a victim to view the injected content (UI:R).

Exploitation

Not listed in CISA KEV, but EPSS is high (0.69552, 99.3rd percentile) and the WPScan references are tagged Exploit, indicating public exploit detail exists.

What to do

  • Update Modern Events Calendar Lite to version 6.4.0 or later.
  • If immediate patching is not possible, restrict contributor and similar low-privilege roles, or disable the plugin until it can be updated.
  • Apply input sanitization and output escaping to Hourly Schedule fields as a compensating control if code changes are feasible.
  • Review and remove any stored Hourly Schedule content containing script or unexpected HTML.
  • Enforce least privilege on WordPress accounts and audit role assignments.

Detection

  • Search event and schedule content in the database for script tags or suspicious HTML in Hourly Schedule fields.
  • Monitor web server and WordPress logs for requests to plugin endpoints containing encoded script payloads.
  • Alert on new or modified schedule entries created by contributor-level accounts.
  • Review WAF or application logs for XSS patterns targeting the plugin's schedule parameters.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-0364 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-4458Webnus modern events calendar lite sql injection vulnerabilityThe Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_ajax_mec_load_single_page' AJAX…EPSS 0.35%9.8CVE-2021-24946Modern Events Calendar Lite unauthenticated SQL injectionThe Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise or escape the time parameter before using it in a SQL statement withi…EPSS 73%analysed9.6CVE-2024-6522Webnus modern events calendar server-side request forgery (ssrf) vulnerabilityThe Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'me…EPSS 0.40%8.8CVE-2024-5441Webnus modern events calendar unrestricted file upload vulnerabilityThe Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image…EPSS 1.1%8.8CVE-2021-24149Webnus modern events calendar lite sql injection vulnerabilityUnvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in th…EPSS 1.5%7.5CVE-2021-24146Webnus modern events calendar lite improper access control vulnerabilityLack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the exp…EPSS 31%7.2CVE-2021-24145Modern Events Calendar Lite plugin arbitrary file upload via CSV importThe Modern Events Calendar Lite WordPress plugin before 5.16.5 failed to properly validate files during import, so a PHP file could be uploaded by se…EPSS 87%analysed6.1CVE-2021-24925Webnus modern events calendar lite cross-site scripting vulnerabilityThe Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_m…EPSS 0.80%

Source: NIST National Vulnerability Database (record CVE-2022-0364), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.