CVE-2024-39630
The Timetable and Event Schedule by MotoPress plugin for WordPress through version 2.4.13 contains a PHP Object Injection vulnerability stemming from unsafe deserialization of untrusted data stored in comment metadata. This flaw allows attackers with Administrator privileges or higher to inject malicious PHP objects, though exploitation depends on the presence of a usable POP chain from other installed plugins or themes. If such a chain exists, an attacker could leverage the vulnerability to remove files, access confidential information, or achieve arbitrary code execution.
Based on public CVE data (MITRE/NVD).