CVE-2020-9459 describes multiple stored Cross-site Scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin for WordPress, affecting versions through 5.1.6. This medium-severity vulnerability (CVSS 5.4) allows authenticated users with minimal permissions to inject malicious JavaScript, HTML, or CSS via Ajax actions, potentially leading to information disclosure or defacement. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness, though it is not listed on the CISA KEV catalog as actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.1.6CPE matchmatch criteria | cpe:2.3:a:webnus:modern_events_calendar_lite:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.