S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24145 Scanner

CVE-2021-24145 scanner - Unrestricted File Upload vulnerability in Modern Events Calendar Lite plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24145
7.2
CVSS

Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Modern Events Calendar Lite
AFFECTED< 5.16.5SAFE ✓≥ 5.16.5
Updated Aug 21, 2026View on NVD →
Detail

The Modern Events Calendar Lite plugin is a popular WordPress plugin used to manage events and calendars on websites. It is a free and easy-to-use plugin that enables website owners to display various events, such as conferences, festivals, concerts, and more, on their website. 

However, researchers recently discovered a serious vulnerability in the plugin, known as CVE-2021-24145. This vulnerability allows an attacker to upload arbitrary files to the website, bypassing the security checks and authorization mechanisms. This means that an attacker can upload malicious PHP files, leading to remote code execution and a potential compromise of the website.

When exploited, this vulnerability can lead to various negative consequences for both the website owner and the website visitors. An attacker can use the uploaded file to gain control of the website, steal sensitive data, or install malware on the website, which can then infect visitors' devices. This can lead to data breaches, financial losses, and reputational damage for the website owner, and security risks for the users.

Fortunately, thanks to the advanced security features of the s4e.io platform, website owners can quickly and easily identify and fix vulnerabilities in their digital assets. With features such as automated vulnerability scanning, real-time threat detection, and expert support, website owners can stay one step ahead of the hackers and protect their website from potential attacks. So if you're concerned about the security of your website, don't hesitate to check out s4e.io and take advantage of its powerful security tools and services.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners are advised to take the following precautions:

  • Update the Modern Events Calendar Lite plugin to the latest version (version 5.16.5 or higher)
  • Disable file uploads in the plugin settings, if file uploads are not needed
  • Restrict access to the plugin files and directories using appropriate permissions and access controls
  • Use a web application firewall to detect and block malicious file uploads and other attacks
  • Regularly scan the website for vulnerabilities using automated tools and perform manual testing to identify and fix security issues

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.