
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32583 is a Missing Authorization (Broken Access Control) vulnerability in the Modern Events Calendar WordPress plugin by Webnus Inc. It allows unauthenticated remote attackers to exploit incorrectly configured access control security levels, potentially performing unauthorized actions. The vulnerability affects all versions of the plugin from n/a through 7.29.0. It was published on March 16, 2026, and assigned a CVSS v3.1 base score of 5.3 (Medium) (Feedly, Patchstack).
The root cause is classified as CWE-862 (Missing Authorization) — the plugin fails to properly verify whether a requesting user has the necessary permissions before executing certain actions or exposing functionality. Because no authentication or privilege check is enforced on the vulnerable endpoint(s), an unauthenticated attacker can send crafted network requests to trigger restricted operations. The attack vector is network-based, requires no user interaction, and has low attack complexity, making it straightforward to exploit remotely (Feedly, Patchstack). Nuclei detection templates for this vulnerability have been added to the ProjectDiscovery nuclei-templates repository, indicating the vulnerability is well-characterized for automated scanning (Nuclei Templates).
Successful exploitation results in a low-integrity impact with no confidentiality or availability impact, according to the CVSS scoring. In practice, an unauthenticated attacker can perform unauthorized write or modification actions within the Modern Events Calendar plugin — such as manipulating event data or plugin settings — without valid credentials. While the direct impact is limited in scope (no data disclosure or service disruption), unauthorized modification of calendar content on public-facing WordPress sites could be used for defacement, spam injection, or as a stepping stone in a broader attack chain (Feedly).
The vulnerability has an EPSS score of approximately 0.027 (2.7%), indicating a relatively low but non-negligible probability of exploitation in the wild. No confirmed in-the-wild exploitation or threat actor attribution has been reported as of the available data. However, Nuclei detection templates have been committed to the ProjectDiscovery nuclei-templates repository across multiple updates, enabling automated scanning and lowering the barrier for opportunistic exploitation (Nuclei Templates). The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
wp-admin/admin-ajax.php action, without supplying authentication credentials or nonces.wp-admin/admin-ajax.php or WordPress REST API endpoints associated with the Modern Events Calendar plugin; repeated requests from a single IP targeting plugin-specific actions.wp-content/plugins/modern-events-calendar/ directory.WordPress site administrators should update the Modern Events Calendar plugin to a version above 7.29.0 as soon as a patched release is available from Webnus Inc. Until a patch is applied, consider temporarily deactivating the plugin if it is not critical to site operations. Additionally, deploying a Web Application Firewall (WAF) — such as those offered by Patchstack, Wordfence, or Cloudflare — can provide virtual patching to block exploitation attempts against this vulnerability (Patchstack).
The vulnerability was reported and disclosed by Patchstack, a WordPress security platform, which assigned it the identifier EUVD-2026-12451. Social media activity on Bluesky noted the CVE shortly after publication. The inclusion of detection templates in the ProjectDiscovery nuclei-templates repository reflects community interest in automated detection. No major vendor statements or significant media coverage beyond standard vulnerability database entries have been identified (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."