The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 7.21.9. This is due improper or insufficient validation of the id property when exporting calendars. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
We have discovered 27,899 live websites that are affected by CVE-2025-5733.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 27,899 live websites (95% of Modern Events Calendar Lite install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 152 versions ( 99% of all versions) |
![]() | 10,577 websites |
![]() | 4,259 websites |
![]() | 2,288 websites |
![]() | 1,101 websites |
![]() | 894 websites |
![]() | 887 websites |
![]() | 666 websites |
![]() | 653 websites |
![]() | 645 websites |
![]() | 472 websites |
.com | 8,208 websites |
.org | 4,598 websites |
.de | 2,783 websites |
.fr | 1,074 websites |
.nl | 956 websites |
.it | 913 websites |
.ch | 527 websites |
.ca | 507 websites |
.net | 482 websites |
.co.uk | 441 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*************************.***.au | ![]() | **,*** | |
******.**.il | ![]() | **,*** | |
********.**.il | ![]() | **,*** | |
**********.***.il | ![]() | **,*** | |
************.org | ![]() | **,*** | |
********.com | ![]() | ***,*** | |
**************.com | ![]() | ***,*** | |
******.net | ![]() | ***,*** | |
***************.fr | ![]() | ***,*** | |
***************.net | ![]() | ***,*** |
FAQ