References https://nvd.nist.gov/vuln/detail/CVE-2021-4458 https://www.cvedetails.com/cve/CVE-2021-4458/ https://github.com/advisories/GHSA-gcj4-979g-33cw https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/modern-events-calendar-lite/modern-events-calendar-lite-630-unauthenticated-sql-injection https://patchstack.com/database/wordpress/plugin/modern-events-calendar-lite/vulnerability/wordpress-modern-events-calendar-lite-plugin-6-3-0-unauthenticated-sql-injection-vulnerability https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2021-4458 https://cve.imfht.com/detail/CVE-2021-4458 https://www.nsfocus.net/vulndb/124664 https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/modern-events-calendar-lite
Related VulnerabilitiesWordpress Events Calendar插件敏感信息泄露漏洞(CVE-2025-9808)PoCCVE-2026-6854: My Calendar < 3.7.9 - Unauthenticated SQL InjectionPoCphpjabbers-event-booking-xss: PHPJabbers Event Booking Calendar - Reflected XSSPoCCVE-2026-40308: My Calendar WordPress Plugin - Information DisclosurePoCCVE-2026-32583: Webnus Inc. Modern Events Calendar - Broken Access ControlPoC用友 NC /portal/pt/oacoSchedulerEvents/deleteEvent SQL 注入漏洞PoCwordpress-events-manager-fpd: WordPress Events Manager - Full Path DisclosurePoCCVE-2024-5333: WordPress Events Calendar 6.8.2.1 - Information DisclosurePoCgoogle-calendar-exposure: Google Calendar - ExposurePoCCVE-2021-4448: Kaswara Modern VC Addons <= 3.0.1 - Missing AuthorizationPoCCVE-2025-9808: The Events Calendar <= 6.15.2 - Information DisclosurePoCwp-the-events-calendar-fpd: WordPress The Events Calendar - Full Path Disclosure金和OA /c6/Jhsoft.Web.calendar/public/Print1.aspx 存在权限管理不当漏洞