What the vulnerability does
01Description
Missing Authorization vulnerability in Webnus Inc. Modern Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Modern Events Calendar: from n/a through 7.29.0.
Explanation of Vulnerability in Simple Terms
02Summary
Modern Events Calendar versions up to 7.29.0 contain an authorization bypass that allows unauthenticated attackers to modify event data over the network. The vulnerability stems from missing access control checks on event modification endpoints. No user interaction is required to exploit this issue. Site administrators should update to a version newer than 7.29.0.
What an attacker can do
03Attacker Capabilities
Modify event data without authentication or permission.
Potential impact on your site
04Site Impact
Attackers can alter or corrupt event information visible to site visitors without logging in.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication required.
Key dates
06Disclosure timeline
March 16, 2026
CVE published
March 16, 2026
Record updated