CVE-2021-24584
The Timetable and Event Schedule plugin versions before 2.4.2 contained an access control flaw that permitted users with the edit_posts capability, such as contributors, to modify timeslots belonging to any event without restriction. The vulnerability was compounded by the absence of CSRF protections, making it possible to exploit the flaw through cross-site requests against authenticated users with sufficient privileges. Additionally, versions prior to 2.3.19 suffered from improper sanitization and escaping in certain fields including descriptions, which could be leveraged to inject and store malicious scripts.
Based on public CVE data (MITRE/NVD).