High severity7.2NVD Advisory· Published Aug 23, 2021· Updated Jun 17, 2026
CVE-2021-24553
CVE-2021-24553
Description
The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Other SQL Injections are also present in the plugin
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:timeline_calendar_project:timeline_calendar:*:*:*:*:*:wordpress:*:*Range: <=1.2
- WordPress/Timeline Calendardescription
- Range: <=1.2
Patches
Vulnerability mechanics
References
2- codevigilant.com/disclosure/2021/wp-plugin-timeline-calendar/nvdExploitThird Party Advisory
- wpscan.com/vulnerability/14c75a00-a52b-430b-92da-5145e5aee30anvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.