CVE · Medium

CVE-2021-24724 — Timetable and Event Schedule by MotoPress [mp-timetable] < 2.3.19

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24724 Timetable and Event Schedule by MotoPress [mp-timetable] < 2.3.19 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.3.19 2.3.19 2021-08-23

CVE-2021-24724

The Timetable and Event Schedule by MotoPress plugin in versions prior to 2.3.19 failed to properly sanitize certain user-supplied parameters, enabling attackers with low-level privileges like author accounts to inject malicious scripts that would execute in the browsers of both administrative and frontend users viewing affected events.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.