peter bassill · operator
$ cve CVE-2021-24145 JSON

CVE-2021-24145 EXPLOIT

7.2
HIGH · CVSS 3.1 · EPSS 87.2% (pctl 100)

Patch early

A public exploit exists.

Description

Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.

Scoring

CVSS7.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS87.2% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2021-03-18
Last modified2026-06-17

Affected (1)

VendorProduct
webnusmodern events calendar lite

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD