S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24946 Scanner

CVE-2021-24946 scanner - SQL Injection (SQLi) vulnerability in Modern Events Calendar Lite plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
6.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24946
9.8
CVSS

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Modern Events Calendar Lite
AFFECTED< 6.1.5SAFE ✓≥ 6.1.5
Updated Sep 10, 2026View on NVD →
Detail

Modern Events Calendar Lite is a popular WordPress plugin used to create and manage events on websites. With the help of this plugin, users can easily and smoothly create and display events with detailed information such as the date, time, location, and more. This plugin has gained popularity for its easy-to-use features and customizable options that offer a hassle-free event management experience to website owners.

However, this plugin has a vulnerability that can pose a huge risk to website security. CVE-2021-24946 is an unauthenticated SQL injection issue that was detected in the Modern Events Calendar Lite plugin version before 6.1.5. This vulnerability allows unauthenticated users to bypass security measures and manipulate the SQL queries that are executed on the database server.

When exploited, this vulnerability can lead to a number of serious consequences. Hackers can use this security flaw to insert their own malicious SQL code into the plugin's database queries, leading to data theft, data alteration, site defacement, and other critical attacks. This can compromise the entire website and all data stored on it, including user data and payment information.

In conclusion, website security should always be a top priority for any website owner or developer. The Modern Events Calendar Lite plugin is a popular WordPress plugin that has a serious vulnerability, which can pose a huge risk to website security. With the pro features of s4e.io, users can quickly and easily learn about vulnerabilities in their digital assets and take necessary precautions to protect their website from potential attacks.

 

REFERENCES

Solution Advice

To protect against CVE-2021-24946 vulnerability, there are a few precautions that website owners can take:

  • Update the Modern Events Calendar Lite plugin to version 6.1.5 or later immediately.
  • Install a trusted WordPress security plugin that can detect and prevent SQL injection attacks.
  • Block unauthorized users from accessing the website using a firewall or other security measures.
  • Regularly backup website data to ensure quick recovery in case of any attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.