Vulnerability record · CVE-2021-24946 · published 13 December 2021
CVE-2021-24946: Modern Events Calendar Lite unauthenticated SQL injection
Webnus · Modern Events Calendar Lite
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise or escape the time parameter before using it in a SQL statement within the mec_load_single_page AJAX action. Because that action is reachable by unauthenticated users, any remote attacker can inject SQL into the site's database. The flaw is rated critical and public exploit code exists.
Description
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable SQL injection with a 9.8 CVSS score, public exploit code and very high EPSS probability.
What it is
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise or escape the time parameter before using it in a SQL statement within the mec_load_single_page AJAX action. Because that action is reachable by unauthenticated users, any remote attacker can inject SQL into the site's database. The flaw is rated critical and public exploit code exists.
Impact
An attacker can read, modify or delete arbitrary data in the WordPress database, including user credentials and site content, and may be able to escalate to full site compromise depending on database privileges.
Attack surface
Reached over the network through the plugin's AJAX endpoint with no authentication and no user interaction required, as reflected in the CVSS vector AV:N/AC:L/PR:N/UI:N. Any site running an affected version with the plugin active is exposed.
Exploitation
Public exploit code is referenced by multiple advisories, and EPSS is 0.728 (99.4th percentile), indicating a high likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild campaign is documented in this record.
What to do
- Update Modern Events Calendar Lite to 6.1.5 or later immediately.
- If patching cannot be done at once, deactivate the plugin until it is updated.
- Add a WAF rule blocking SQL injection patterns on the mec_load_single_page AJAX action.
- Audit the WordPress database and user accounts for signs of tampering after exposure.
- Restrict database account privileges used by the WordPress installation to limit injection impact.
Detection
- Review web server and WAF logs for requests to admin-ajax.php with action=mec_load_single_page and suspicious time parameter values.
- Search for SQL metacharacters or UNION/boolean patterns in the time parameter of plugin AJAX requests.
- Monitor database logs for anomalous queries or errors originating from the WordPress application.
- Check for unexpected administrative users or content changes that could indicate post-exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/165742/WordPress-Modern-Events-Calendar-6.1-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/Hacker5preme/Exploits/tree/main/Wordpress/CVE-2021-24946 | ExploitThird Party Advisory |
| https://wpscan.com/vulnerability/09871847-1d6a-4dfe-8a8c-f2f53ff87445 | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/165742/WordPress-Modern-Events-Calendar-6.1-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/Hacker5preme/Exploits/tree/main/Wordpress/CVE-2021-24946 | ExploitThird Party Advisory |
| https://wpscan.com/vulnerability/09871847-1d6a-4dfe-8a8c-f2f53ff87445 | ExploitThird Party Advisory |
Track CVE-2021-24946 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-24946), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.