Webnus develops calendar and events management plugins for WordPress that are widely embedded in small-business and community websites, placing them in a prominent but specialized niche of the vulnerability landscape. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the exposure recurs across its Modern Events Calendar product line through application-layer weakness classes including cross-site scripting, SQL injection, unrestricted file uploads, and access-control flaws that are characteristic of web-facing WordPress extensions. Defenders should treat Webnus plugin updates as a patching priority for sites where event management is deployed; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webnus over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24946CRITICAL The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX ac | Dec 13, 2021 | 9.8 | 89 | NO | YES |
CVE-2021-24145HIGH Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by adm | Mar 18, 2021 | 7.2 | 89 | NO | YES |
CVE-2021-24146HIGH Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthentic | Mar 18, 2021 | 7.5 | 61 | NO | YES |
CVE-2022-0364MEDIUM The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as cont | Mar 21, 2022 | 5.4 | 56 | NO | NO |
CVE-2021-4458CRITICAL The Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_ajax_mec_load_single_page' AJAX action in all versions up to, | Jul 12, 2025 | 9.8 | 31 | NO | NO |
CVE-2024-6522CRITICAL The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'mec_fes_form' AJAX function. This | Aug 7, 2024 | 9.6 | 29 | NO | NO |
CVE-2024-5441HIGH The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image function in all versions up to | Jul 9, 2024 | 8.8 | 28 | NO | NO |
CVE-2021-24149HIGH Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when | Mar 18, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-25046MEDIUM The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the | Jan 17, 2022 | 5.4 | 21 | NO | NO |
CVE-2021-24925MEDIUM The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to bot | Dec 13, 2021 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webnus.
Media articles that mention a CVE ID that affects a product developed by Webnus — matched by CVE ID, not by vendor name.