CVE · Medium

CVE-2021-24585 — Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24585 Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.2 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.5 < 2.4.2 2.4.2 2021-08-23

CVE-2021-24585

The Timetable and Event Schedule plugin before version 2.4.0 exposed sensitive user information including hashed passwords, usernames, and email addresses when retrieving event timeslot data from the API, provided the requesting user had the edit_posts capability. When combined with another vulnerability allowing arbitrary user ID specification in timeslot modifications, attackers with low-privilege roles like author could enumerate and extract this personal data by iterating through different user IDs.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.