WordPress Plugin Vulnerabilities

Timetable and Event Schedule by MotoPress < 2.4.16 - Contributor+ Event Disclosure via IDOR

Description

The plugin does not verify a user has access to a specific event when duplicating, leading to arbitrary event disclosure when to users with a role as low as Contributor.

Proof of Concept

Affects Plugins

Fixed in 2.4.16

References

Classification

Type
IDOR
CWE
CVSS

Miscellaneous

Original Researcher
bRpsd
Submitter
bRpsd
Submitter twitter
NA
Verified
Yes

Timeline

Publicly Published
2025-11-12 (about 1 month ago)
Added
2025-11-12 (about 1 month ago)
Last Updated
2025-11-12 (about 1 month ago)

Other