vendor:
Modern Events Calendar Lite
by:
Ron Jost (Hacker5preme)
7,5
CVSS
HIGH
Unauthenticated Access
863, 284
CWE
Product Name: Modern Events Calendar Lite
Affected Version From: Before 5.16.5
Affected Version To: 5.16.5
Patch Exists: YES
Related CWE: CVE-2021-24146
CPE: a:webnus:modern_events_calendar_lite
Metasploit:
N/A
Other Scripts:
N/A
Tags: cve2021,wpscan,packetstorm,wordpress,wp-plugin,cve
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Nuclei Metadata: {'max-request': 1, 'framework': 'wordpress', 'vendor': 'webnus', 'product': 'modern_events_calendar_lite'}
Platforms Tested: Ubuntu 18.04
2021
WordPress Plugin Modern Events Calendar 5.16.2 – Event export (Unauthenticated)
WordPress Modern Events Calendar Lite before 5.16.5 does not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format.
Mitigation:
Upgrade to version 5.16.5 or later