Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
CVE-2021-24145 — Unrestricted File Upload in Modern Events Calendar Lite
Severity
7.2HIGHNVD
EPSS
90.5%
top 0.39%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMar 18
Latest updateMay 24
Description
Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9
Affected Packages1 packages
🔴Vulnerability Details
2💥Exploits & PoCs
2Exploit-DB
▶
Nuclei▶
WordPress Modern Events Calendar Lite <5.16.5 - Authenticated Arbitrary File Upload