CVE Database /
CVE-2025-12954
CVE · Low
CVE-2025-12954 — Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.16
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-12954
|
Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.16 |
Authorization Bypass Through User-Controlled Key |
Low
2.7
|
< 2.4.16
|
2.4.16 |
2025-11-12 |
—
|
CVE-2025-12954
A vulnerability exists in Timetable and Event Schedule plugin versions prior to 2.4.15 that allows authorized users with contributor privileges or higher to access sensitive information about events through the 'mptt_duplicate_event' action due to inadequate key validation. This flaw can be exploited by attackers who have been granted elevated permissions, enabling them to potentially view unauthorized event details. The vulnerability affects all plugin versions up to 2.4.15.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings