Modern Events Calendar Lite <= 5.16.4 - Unauthenticated Events Export

2021-01-29 00:00
Nguyen Van Khanh

Strategic Overview

Status
Patched in 5.16.5
Affected Version<= 5.16.4
CVSS7.5High
CVECVE-2021-24146
View all Modern Events Calendar Lite vulnerabilities

Vulnerability Overview

Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.

Technical Analysis

REMEDIATION: Update to version 5.16.5, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C