S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-24146 Scanner

Detects 'Improper Access Control' vulnerability in Modern Events Calendar Lite plugin for WordPress affects v. before 5.16.5.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24146
7.5
CVSS

Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Modern Events Calendar Lite
AFFECTED< 5.16.5SAFE ✓≥ 5.16.5
Updated Aug 21, 2026View on NVD →
Detail

Modern Events Calendar Lite is a WordPress plugin that allows users to create and manage events on their websites. It offers various features like recurring events, location maps, and ticketing options to make event management easy and efficient. However, recent news revealed a severe security flaw in this popular plugin that can compromise user data.

CVE-2021-24146 vulnerability is one of the critical security issues that Modern Events Calendar Lite WordPress plugin suffers from. It arises due to the lack of authorization checks that restrict unauthenticated user access to the exported files. This problem makes it easy for malicious actors to gain access to the website's data, including events, files, and all related data in CSV or XML format. 

When exploited, this vulnerability can result in unauthorized data access, which can be disastrous for businesses, organizations, and even government bodies that rely heavily on the proper management of events and its resources. The damage caused can range from reputation loss and loss of customer trust to financial loss, potential lawsuits, and regulatory investigations.

Protecting your website from potential vulnerabilities is a crucial step in ensuring the safety and security of your digital assets. With s4e.io's pro features, you can quickly and easily learn about the vulnerabilities in your websites and take necessary actions to prevent them from happening. Stay ahead of the curve by subscribing to our advanced security features and enjoy the peace of mind that comes with being fully protected against cyber threats.

 

REFERENCES

Solution Advice

Protection against this type of vulnerability can easily be implemented by taking a few precautions, including: 

  • Installing the latest patched version of the affected plugin (version 5.16.5 or later).
  • Disabling the export feature for users who don't have the right permission to access the feature.
  • Removing the plugin if possible or disabling access to the plugin's features until a full patch has been applied.
  • Adding an additional authentication layer to the website's login process (e.g., 2FA) to reduce the risk of unauthorized access.
  • Regularly monitoring the website for unauthorized access or unusual activities and responding promptly if such threats are detected.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24146 scanner - Improper Access Control vulnerability in Modern Events Calendar Lite plugin for WordPress S4E