CVE-2021-24146
high · 7.5A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.
7.5
CVSS
31.0%
EPSS (exploit prob.)
98th
EPSS percentile
2021-03-18
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weaknesses
CWE-284CWE-862
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| webnus | modern_events_calendar_lite | < 5.16.5 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/163345/WordPress-Modern-Events-Calendar-5.16.2-Information-Disclosure.html
- https://wpscan.com/vulnerability/c7b1ebd6-3050-4725-9c87-0ea525f8fecc
- http://packetstormsecurity.com/files/163345/WordPress-Modern-Events-Calendar-5.16.2-Information-Disclosure.html
- https://wpscan.com/vulnerability/c7b1ebd6-3050-4725-9c87-0ea525f8fecc
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-24146