← back
CVE-2021-24146CWE-284

Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 31%
from disclosure to weapon106 days
Published on NVDMar 18
1st PoC+106d
exploitation probability
31%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.