← Vulnerability feed

Vulnerability record · CVE-2021-24946 · published 13 December 2021

CVE-2021-24946: Modern Events Calendar Lite unauthenticated SQL injection

Webnus · Modern Events Calendar Lite

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise or escape the time parameter before using it in a SQL statement within the mec_load_single_page AJAX action. Because that action is reachable by unauthenticated users, any remote attacker can inject SQL into the site's database. The flaw is rated critical and public exploit code exists.

9.8 CVSS 3.1 Critical EPSS 73% · top 0.6% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable SQL injection with a 9.8 CVSS score, public exploit code and very high EPSS probability.

What it is

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise or escape the time parameter before using it in a SQL statement within the mec_load_single_page AJAX action. Because that action is reachable by unauthenticated users, any remote attacker can inject SQL into the site's database. The flaw is rated critical and public exploit code exists.

Impact

An attacker can read, modify or delete arbitrary data in the WordPress database, including user credentials and site content, and may be able to escalate to full site compromise depending on database privileges.

Attack surface

Reached over the network through the plugin's AJAX endpoint with no authentication and no user interaction required, as reflected in the CVSS vector AV:N/AC:L/PR:N/UI:N. Any site running an affected version with the plugin active is exposed.

Exploitation

Public exploit code is referenced by multiple advisories, and EPSS is 0.728 (99.4th percentile), indicating a high likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild campaign is documented in this record.

What to do

  • Update Modern Events Calendar Lite to 6.1.5 or later immediately.
  • If patching cannot be done at once, deactivate the plugin until it is updated.
  • Add a WAF rule blocking SQL injection patterns on the mec_load_single_page AJAX action.
  • Audit the WordPress database and user accounts for signs of tampering after exposure.
  • Restrict database account privileges used by the WordPress installation to limit injection impact.

Detection

  • Review web server and WAF logs for requests to admin-ajax.php with action=mec_load_single_page and suspicious time parameter values.
  • Search for SQL metacharacters or UNION/boolean patterns in the time parameter of plugin AJAX requests.
  • Monitor database logs for anomalous queries or errors originating from the WordPress application.
  • Check for unexpected administrative users or content changes that could indicate post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-24946 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-4458Webnus modern events calendar lite sql injection vulnerabilityThe Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_ajax_mec_load_single_page' AJAX…EPSS 0.35%9.6CVE-2024-6522Webnus modern events calendar server-side request forgery (ssrf) vulnerabilityThe Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'me…EPSS 0.40%8.8CVE-2024-5441Webnus modern events calendar unrestricted file upload vulnerabilityThe Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image…EPSS 1.1%8.8CVE-2021-24149Webnus modern events calendar lite sql injection vulnerabilityUnvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in th…EPSS 1.5%7.5CVE-2021-24146Webnus modern events calendar lite improper access control vulnerabilityLack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the exp…EPSS 31%7.2CVE-2021-24145Modern Events Calendar Lite plugin arbitrary file upload via CSV importThe Modern Events Calendar Lite WordPress plugin before 5.16.5 failed to properly validate files during import, so a PHP file could be uploaded by se…EPSS 87%analysed6.1CVE-2021-24925Webnus modern events calendar lite cross-site scripting vulnerabilityThe Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_m…EPSS 0.80%5.4CVE-2022-30533Webnus modern events calendar lite cross-site scripting vulnerabilityCross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject an arbitr…EPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2021-24946), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.