CVE-2026-11349

HIGH

Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_load_more

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-11349. PoCs published by exploitintel.

AI-analyzed exploit summary Unauthenticated blind SQL injection in Modern Events Calendar Lite (< 7.34.0) via the `mec_list_load_more` AJAX handler. The exploit uses time-based and boolean oracles to extract arbitrary database content, including admin credentials and password hashes, without requiring authentication or a nonce.

Description

The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection vulnerability that allows attackers to extract sensitive data from the database.

Exploits (1)

github WORKING POC 7 stars
by exploitintel · cpoc
https://github.com/exploitintel/eip-pocs-and-cves/tree/main/CVE-2026-11349

Unauthenticated blind SQL injection in Modern Events Calendar Lite (< 7.34.0) via the `mec_list_load_more` AJAX handler. The exploit uses time-based and boolean oracles to extract arbitrary database content, including admin credentials and password hashes, without requiring authentication or a nonce.

Classification
Working Poc 99%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Modern Events Calendar Lite (WordPress plugin) versions < 7.34.0
No auth needed
Prerequisites: Target must have Modern Events Calendar Lite installed (version < 7.34.0) · Network access to the WordPress `admin-ajax.php` endpoint · No rate limiting or WAF blocking time-based SQLi payloads
mistral-large-3 · analyzed Aug 08, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/572229cb-8a09-406d-8623-7d6b553bfdde/

Scores

CVSS v3 8.6
EPSS 0.0032
EPSS Percentile 24.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (2)
None/Modern Event Calendar Pro < 7.34.0
None/Modern Events Calendar Lite < 7.34.0
Published Jul 20, 2026
Tracked Since Jul 20, 2026