PLUGIN SECURITY
Is Mp Timetable safe?
Smart event organizer and time-management tool with a clean minimalist design for featuring your timetables and upcoming events.
What this plugin does
- Slug:
mp-timetable - Author: jetmonsters
- 30000+ active installs
- 86/100 rating (69 reviews on wordpress.org)
- 933540 all-time downloads
- On WordPress.org since 2016-04-04
calendarEventevents calendarscheduletimetable
Maintenance status
- Latest known version: 2.4.18
- Last updated: 2026-06-23 2:29pm GMT
- Tested up to WordPress: 7.0.4
- Max supported PHP (analyzed): <8.0
Known vulnerabilities
9 known CVEs on file for Mp Timetable. Reported between 2020 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-9228 | Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.17 | Authorization Bypass Through User-Controlled Key | Medium 4.3 | < 2.4.17 | 2.4.17 | 2026-05-27 | ✓ fixed in latest |
| CVE-2025-12954 | Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.16 | Authorization Bypass Through User-Controlled Key | Low 2.7 | < 2.4.16 | 2.4.16 | 2025-11-12 | ✓ fixed in latest |
| CVE-2024-39630 | Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.14 | Deserialization of Untrusted Data | Medium 5.5 | < 2.4.14 | 2.4.14 | 2024-07-22 | ✓ fixed in latest |
| CVE-2024-3342 | Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.12 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.9 | < 2.4.12 | 2.4.12 | 2024-04-26 | ✓ fixed in latest |
| CVE-2021-24585 | Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.2 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 6.5 | < 2.4.2 | 2.4.2 | 2021-08-23 | ✓ fixed in latest |
| CVE-2021-24583 | Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.2 | Improper Access Control | Medium 4.3 | < 2.4.2 | 2.4.2 | 2021-08-23 | ✓ fixed in latest |
| CVE-2021-24584 | Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.4.2 | 2.4.2 | 2021-08-23 | ✓ fixed in latest |
| CVE-2021-24724 | Timetable and Event Schedule by MotoPress [mp-timetable] < 2.3.19 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.3.19 | 2.3.19 | 2021-08-23 | ✓ fixed in latest |
+ 1 more known vulnerability
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2020-36840 | Timetable and Event Schedule by MotoPress [mp-timetable] < 2.3.9 | Missing Authorization | High 7.3 | < 2.3.9 | 2.3.9 | 2020-04-21 | ✓ fixed in latest |
How to fix it
Keep Mp Timetable updated — 2.4.18 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- The Events Calendar — 600000+ active installs — 84/100 (2450)
- Events Manager – Calendar, Bookings, Tickets, and more! — 70000+ active installs — 84/100 (547) — max PHP <8.0
- SimplyBook.me – Booking and reservations calendar — 30000+ active installs — 90/100 (17) — max PHP 8.4
- WP Events Manager — 30000+ active installs — 54/100 (13) — max PHP 8.4
- WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce — 20000+ active installs — 80/100 (247)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.