CVE-2026-11349 is an unauthenticated SQL injection vulnerability affecting Modern Event Calendar Pro and Modern Events Calendar Lite for WordPress before version 7.34.0. The flaw is caused by improper sanitization and escaping of a request parameter before it is incorporated into a SQL statement. The vulnerable code path is exposed through an AJAX action that is accessible to unauthenticated users. Successful exploitation allows a remote attacker to inject arbitrary SQL into backend database queries and extract sensitive information from the WordPress database.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains two Python utilities and a detailed README for CVE-2026-11349 affecting Webnus Modern Events Calendar Lite. The main exploit file, `mec-unauth-sqli-poc.py`, is a standalone Python 3 proof-of-concept that targets the unauthenticated WordPress AJAX endpoint `/wp-admin/admin-ajax.php` with action `mec_list_load_more`. It injects SQL through `atts[include][]` or `atts[exclude][]`, measures response timing, calibrates a threshold, and performs blind time-based extraction of scalar database values. Built-in extraction modes include DB version, current DB user, first WordPress login, and `user_login:user_pass` hash output from `wp_users`. It supports host-header override, optional TLS verification disablement, configurable sleep/delay, and custom SQL subqueries. The second code file, `mec-vuln-scanner.py`, is not an exploit but a detection/inventory tool. It fingerprints likely MEC installations using homepage HTML markers, plugin asset paths under `/wp-content`, plugin slugs, and `readme.txt` stable-tag parsing. An optional `--active-check` sends a benign integer request to the same AJAX action to determine whether the vulnerable endpoint is live, but it intentionally avoids SQL metacharacters and data extraction. Overall structure is simple: README documents root cause, affected versions, exploitation path, and disclosure context; one Python PoC performs actual unauthenticated blind SQLi exploitation; one Python scanner performs safe detection. This is a real exploit repository, not just documentation, and the exploit is operational rather than weaponized because it includes a working hardcoded extraction workflow but is not integrated into a larger exploitation framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.