CVE-2025-5733

Modern Events Calendar <= 7.21.9 - Information Exposure

The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 7.21.9. This is due improper or insufficient validation of the id property when exporting calendars. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.


We have discovered 27,899 live websites that are affected by CVE-2025-5733.

Run a Free Instant Scan




Affected Software

Product  Modern Events Calendar Lite
Category Wordpress Plugins
Vulnerable Domains27,899 live websites (95% of Modern Events Calendar Lite install base)
Vulnerable Versions
  • from 0 through 7.21.9
Vulnerable Versions Count152 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-201 Insertion of Sensitive Information Into Sent Data



Details

  • Published - Jun 6, 2025
  • Updated - Jun 6, 2025

Credits

  • Abdullah Shittu (finder)

Website Distribution by Country

Number of websites using CVE-2025-5733
United States10,577 websites



Germany4,259 websites
France2,288 websites
Italy1,101 websites
GB894 websites
Netherlands887 websites
Spain666 websites
Brazil653 websites
Switzerland645 websites
Denmark472 websites

Website Distribution by TLD

Number of websites using CVE-2025-5733
.com8,208 websites
.org4,598 websites
.de2,783 websites
.fr1,074 websites
.nl956 websites
.it913 websites
.ch527 websites
.ca507 websites
.net482 websites
.co.uk441 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-5733

Top websites that are affected by CVE-2025-5733. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************************.***.au United States**,***
******.**.il United States**,***
********.**.il Israel**,***
**********.***.il Israel**,***
************.org Germany**,***
********.com United States***,***
**************.com United States***,***
******.net Spain***,***
***************.fr United States***,***
***************.net Germany***,***
See full domain list

FAQ

CVE-2025-5733 is Insertion of Sensitive Information Into Sent Data in Modern Events Calendar Lite
A total of 27,899 websites have been identified as vulnerable to CVE-2025-5733, based on global website indexing conducted by WebTechSurvey.
The Modern Events Calendar Lite is affected by the CVE-2025-5733 vulnerability.
Modern Events Calendar Lite versions up to and including 7.21.9 are vulnerable to CVE-2025-5733.