CVE-2025-5733
BaseFortify
Publication date: 2025-06-06
Last updated on: 2025-06-06
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-201 | The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in the Modern Events Calendar Lite plugin for WordPress allows unauthenticated attackers to retrieve the full file path of the web application due to improper validation of the id property when exporting calendars. This is known as Full Path Disclosure and affects all versions up to and including 7.21.9.
How can this vulnerability impact me? :
The vulnerability itself only reveals the full path of the web application, which is not directly harmful. However, this information can be used by attackers to facilitate other attacks if additional vulnerabilities exist on the affected website.