← back to popular plugins
wordfence / plugin · mp-timetable

Timetable and Event Schedule by MotoPress

mp-timetable
total installs
30,000
total vulns
1
critical
0
high
0
medium
1
low
0
latest vuln
patched
1
unpatched
0
avg time to patch
vulnerabilities (1)
Timetable and Event Schedule by MotoPress <= 2.4.15 - Insecure Direct Object Reference to Authenticated (Contributor+) Event Disclosure
medium ✓ patched
cvss score 5.3
cwe CWE-639: Authorization Bypass Through User-Controlled Key
published Nov 12, 2025
The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.15 via the 'mptt_duplicate_event' action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to retrieve arbitrary event details.