The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function called via a nopriv AJAX action in versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to call that function and perform a wide variety of actions such as including random template, injecting malicious web scripts, and more.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-30792 The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function called via a nopriv AJAX action in versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to call that function and perform a wide variety of actions such as including random template, injecting malicious web scripts, and more.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00513}

epss

{'score': 0.005}


Wed, 30 Oct 2024 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:motopress:timetable_and_event_schedule:*:*:*:*:*:wordpress:*:*

Wed, 16 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Motopress
Motopress timetable And Event Schedule
CPEs cpe:2.3:a:motopress:timetable_and_event_schedule:*:*:*:*:*:*:*:*
Vendors & Products Motopress
Motopress timetable And Event Schedule
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 07:45:00 +0000

Type Values Removed Values Added
Description The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function called via a nopriv AJAX action in versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to call that function and perform a wide variety of actions such as including random template, injecting malicious web scripts, and more.
Title Timetable and Event Schedule by MotoPress <= 2.3.8 - Missing Authorization
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-10-16T17:26:20.758Z

Reserved: 2024-10-15T18:44:28.632Z

Link: CVE-2020-36840

cve-icon Vulnrichment

Updated: 2024-10-16T17:13:36.447Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-16T08:15:03.710

Modified: 2024-10-30T21:06:30.517

Link: CVE-2020-36840

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.