Vulnerability Description
Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an authenticated SQL Injection issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Webnus | Modern Events Calendar Lite | < 5.16.6 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/26819680-22a8-4348-b63d-dc52c0d50ed0ExploitThird Party Advisory
- https://wpscan.com/vulnerability/26819680-22a8-4348-b63d-dc52c0d50ed0ExploitThird Party Advisory
FAQ
What is CVE-2021-24149?
CVE-2021-24149 is a vulnerability with a CVSS score of 8.8 (HIGH). Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an aut...
How severe is CVE-2021-24149?
CVE-2021-24149 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24149?
Check the references section above for vendor advisories and patch information. Affected products include: Webnus Modern Events Calendar Lite.