ZeroHour

CVE-2021-24146

PoC ×2
CVSS 3.1
7.5 high
EPSS
31%p98
Published
()
Modified
Description

Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.

Vendors
webnus
Products
modern events calendar lite
Ecosystems
WordPress
Weakness
CWE-284, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.