Description
The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the action_get_event_data due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to enumerate timeslot IDs and read the full WP_Post object — including post_content, post_excerpt, post_status, and post_author — of draft, pending, and private mp-event posts belonging to other users, along with their associated raw timeslot descriptions.
Published: 2026-05-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Timetable and Event Schedule by MotoPress plugin for WordPress contains an insecure direct object reference in the action_get_event_data endpoint. The function accepts a user‑controlled key without proper validation, allowing authenticated users with contributor level access and above to specify arbitrary timeslot IDs. This flaw enables attackers to enumerate timeslot IDs and retrieve the full WP_Post object for mp‑event posts, including post_content, post_excerpt, post_status, and post_author, for draft, pending, and private events owned by other users, effectively exposing sensitive event details.

Affected Systems

JetMonsters’ Timetable and Event Schedule by MotoPress plugin, all releases up to and including version 2.4.16, are vulnerable. Every WordPress site installing any of these plugin versions is affected. Site owners should verify the installed plugin version and apply an update when available.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation to date. Attackers must be authenticated and possess at least contributor permissions to leverage the flaw. Successful exploitation results in confidentiality loss—private or draft event data can be read by malicious contributors, potentially aiding planning or espionage linked to the site’s event management.

Generated by OpenCVE AI on May 28, 2026 at 05:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Timetable and Event Schedule by MotoPress plugin to the latest available version once the vendor releases a fix for the action_get_event_data validation issue.
  • If an immediate update cannot be performed, limit the exposure by restricting the action_get_event_data capability to administrator roles only, using WordPress role management or a security plugin that enforces capability checks.
  • Review and tighten contributor and other role permissions on the WordPress site, removing any unnecessary capabilities that could enable unwanted access to event data until a patch is applied.

Generated by OpenCVE AI on May 28, 2026 at 05:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 28 May 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 May 2026 04:45:00 +0000

Type Values Removed Values Added
Description The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the action_get_event_data due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to enumerate timeslot IDs and read the full WP_Post object — including post_content, post_excerpt, post_status, and post_author — of draft, pending, and private mp-event posts belonging to other users, along with their associated raw timeslot descriptions.
Title Timetable and Event Schedule by MotoPress <= 2.4.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via action_get_event_data Function
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-05-28T10:37:17.809Z

Reserved: 2026-05-21T18:33:07.265Z

Link: CVE-2026-9228

cve-icon Vulnrichment

Updated: 2026-05-28T10:37:13.188Z

cve-icon NVD

Status : Deferred

Published: 2026-05-28T05:16:39.447

Modified: 2026-05-28T13:45:25.260

Link: CVE-2026-9228

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T06:00:11Z

Weaknesses