{"id":"CVE-2021-24147","details":"Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not sanitise the mic_comment field (Notes on time) when adding/editing an event, allowing users with privilege as low as author to add events with a Cross-Site Scripting payload in them, which will be triggered in the frontend when viewing the event.","modified":"2026-07-09T05:13:43.076707Z","published":"2021-03-18T15:15:15.557Z","references":[{"type":"EVIDENCE","url":"https://wpscan.com/vulnerability/0f9ba284-5d7e-4092-8344-c68316b0146f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/webnuswp/modern-events-calendar-lite","events":[{"introduced":"0"},{"fixed":"2cf923ae6ac8957825b179a850fc8e41fac98bc9"}],"database_specific":{"cpe":"cpe:2.3:a:webnus:modern_events_calendar_lite:*:*:*:*:*:wordpress:*:*","extracted_events":[{"introduced":"0"},{"fixed":"5.16.5"}],"source":"CPE_RANGE"}}],"versions":["5.16.2","5.16.1","5.16.0","5.15.5","5.15.0","5.14.0","5.13.6","5.13.5","5.13.1","5.13.0","5.12.6","5.12.5","5.12.0","5.11.5","5.11.0","5.10.5","5.10.0","5.9.5","5.9.0","5.8.5","5.8.0","5.7.5","5.7.0","5.6.5","5.6.1","5.6.0","5.5.0","5.4.6","5.4.5","5.4.0","5.3.5","5.3.0","5.2.7","5.2.6","5.2.5","5.2.3","5.2.2","5.2.1","5.2.0","5.1.8","5.1.7","5.1.6","5.1.5","5.1.0","5.0.5","5.0.2","5.0.1","5.0.0","v4.9.5","v4.9.0","4.8.5","4.8.3","4.8.2","4.8.1","4.7.7","v4.7.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-24147.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}