WP Clinic
Log in Sign up

CVE · Medium

CVE-2026-9228 — Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.17

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-9228 Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.17 Authorization Bypass Through User-Controlled Key Medium 4.3 < 2.4.17 2.4.17 2026-05-27

CVE-2026-9228

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the action_get_event_data due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to enumerate timeslot IDs and read the full WP_Post object — including post_content, post_excerpt, post_status, and post_author — of draft, pending, and private mp-event posts belonging to other users, along with their associated raw timeslot descriptions.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.