CVE · Medium

CVE-2026-9228 — Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.17

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-9228 Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.17 Authorization Bypass Through User-Controlled Key Medium 4.3 < 2.4.17 2.4.17 2026-05-27

CVE-2026-9228

A security flaw exists in Timetable and Event Schedule by MotoPress plugin for WordPress, affecting versions up to 2.4.16. The issue arises from inadequate verification of a user-supplied parameter in the action_get_event_data function, allowing attackers with contributor-level access or higher to retrieve sensitive information about other users' unpublished events. This includes details such as post content and authorship, which can be accessed by exploiting this vulnerability.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.