CVE Database /
CVE-2026-9228
CVE · Medium
CVE-2026-9228 — Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.17
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-9228
|
Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.17 |
Authorization Bypass Through User-Controlled Key |
Medium
4.3
|
< 2.4.17
|
2.4.17 |
2026-05-27 |
—
|
CVE-2026-9228
A security flaw exists in Timetable and Event Schedule by MotoPress plugin for WordPress, affecting versions up to 2.4.16. The issue arises from inadequate verification of a user-supplied parameter in the action_get_event_data function, allowing attackers with contributor-level access or higher to retrieve sensitive information about other users' unpublished events. This includes details such as post content and authorship, which can be accessed by exploiting this vulnerability.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings