High severity8.8NVD Advisory· Published Jun 14, 2021· Updated Jun 17, 2026
CVE-2021-24341
CVE-2021-24341
Description
When deleting a date in the Xllentech English Islamic Calendar WordPress plugin before 2.6.8, the year_number and month_number POST parameters are not sanitised, escaped or validated before being used in a SQL statement, leading to SQL injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:xllentech:english_islamic_calendar:*:*:*:*:*:wordpress:*:*Range: <2.6.8
- WordPress/Xllentech English Islamic Calendardescription
- Range: <2.6.8
Patches
Vulnerability mechanics
References
2- wpscan.com/vulnerability/1eba1c73-a19b-4226-afec-d27c48388a04nvdPatchThird Party Advisory
- codevigilant.com/disclosure/2021/xllentech-english-islamic-calendar/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.