9.8
CVSSv3

CVE-2021-24946

Published: 13/12/2021 Updated: 04/02/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Modern Events Calendar Lite WordPress plugin prior to 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

webnus modern events calendar lite

Exploits

WordPress Modern Events Calendar plugin versions 61 and below suffer from an unauthenticated remote SQL injection vulnerability ...