CVE Database /
CVE-2021-24585
CVE · Medium
CVE-2021-24585 — Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24585
|
Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.2 |
Exposure of Sensitive Information to an Unauthorized Actor |
Medium
6.5
|
< 2.4.2
|
2.4.2 |
2021-08-23 |
—
|
CVE-2021-24585
The Timetable and Event Schedule plugin before version 2.4.0 exposed sensitive user information including hashed passwords, usernames, and email addresses when retrieving event timeslot data from the API, provided the requesting user had the edit_posts capability. When combined with another vulnerability allowing arbitrary user ID specification in timeslot modifications, attackers with low-privilege roles like author could enumerate and extract this personal data by iterating through different user IDs.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings