CVE-2026-73339: WordPress Modern Events Calendar plugin < 7.35.0 - SQL Injection vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
Affected Software
1 affected component
wordpress/Modern Events Calendar<7.35.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Modern Events Calendar pluginto a version that resolves this vulnerability.Fixed in 7.35.0
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Sites running a version earlier than 7.35.0 are affected. The issue is remotely reachable and does not require authentication or user interaction.
2
What does an attacker need to exploit this vulnerability?
An attacker can exploit the issue over the network with low attack complexity. No privileges or user interaction are required.
3
What is the remediation?
Upgrade the Modern Events Calendar plugin to version 7.35.0 or later. The provided information does not identify a temporary mitigation if upgrading cannot be performed immediately.