Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
Severity
7.5HIGH
EPSS
75.4%
top 1.11%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMar 18
Latest updateMay 24

Description

Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-2qh8-fp5p-2xx2: Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 52022-05-24
CVEList
Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export2021-03-18

💥Exploits & PoCs

2
Exploit-DB
Wordpress Plugin Modern Events Calendar 5.16.2 - Event export (Unauthenticated)2021-07-02
Nuclei
WordPress Modern Events Calendar Lite <5.16.5 - Sensitive Information Disclosure
CVE-2021-24146 (HIGH CVSS 7.5) | Lack of authorisation checks in the | cvebase.io