CVE · Low

CVE-2025-12954 — Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.16

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12954 Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.16 Authorization Bypass Through User-Controlled Key Low 2.7 < 2.4.16 2.4.16 2025-11-12

CVE-2025-12954

A vulnerability exists in Timetable and Event Schedule plugin versions prior to 2.4.15 that allows authorized users with contributor privileges or higher to access sensitive information about events through the 'mptt_duplicate_event' action due to inadequate key validation. This flaw can be exploited by attackers who have been granted elevated permissions, enabling them to potentially view unauthorized event details. The vulnerability affects all plugin versions up to 2.4.15.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.