CVE Database /
CVE-2021-24583
CVE · Medium
CVE-2021-24583 — Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24583
|
Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.2 |
Improper Access Control |
Medium
4.3
|
< 2.4.2
|
2.4.2 |
2021-08-23 |
—
|
CVE-2021-24583
The Timetable and Event Schedule plugin prior to version 2.4.2 contains an access control vulnerability that permits users with the edit_posts capability or higher, such as contributors, to remove timeslots from any events without authorization. The plugin also fails to implement CSRF protection on the timeslot deletion function, enabling attackers to execute this action through cross-site request forgery attacks against authenticated users possessing sufficient permissions.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings