CVE-2021-24946 is an unauthenticated SQL injection vulnerability affecting the Modern Events Calendar Lite WordPress plugin versions prior to 6.1.5. This critical flaw, with a CVSS score of 9.8, allows unauthenticated attackers to execute arbitrary SQL commands due to improper sanitization of the 'time' parameter in an AJAX action. While not listed in CISA's KEV catalog, public exploit modules for Metasploit and Nuclei, along with an ExploitDB entry, confirm readily available exploit code. Despite its high severity and ease of exploitation, there is minimal community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.1.5CPE matchmatch criteria | cpe:2.3:a:webnus:modern_events_calendar_lite:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.