Impact
The Timetable and Event Schedule by MotoPress plugin for WordPress contains an insecure direct object reference in the action_get_event_data endpoint. The function accepts a user‑controlled key without proper validation, allowing authenticated users with contributor level access and above to specify arbitrary timeslot IDs. This flaw enables attackers to enumerate timeslot IDs and retrieve the full WP_Post object for mp‑event posts, including post_content, post_excerpt, post_status, and post_author, for draft, pending, and private events owned by other users, effectively exposing sensitive event details.
Affected Systems
JetMonsters’ Timetable and Event Schedule by MotoPress plugin, all releases up to and including version 2.4.16, are vulnerable. Every WordPress site installing any of these plugin versions is affected. Site owners should verify the installed plugin version and apply an update when available.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation to date. Attackers must be authenticated and possess at least contributor permissions to leverage the flaw. Successful exploitation results in confidentiality loss—private or draft event data can be read by malicious contributors, potentially aiding planning or espionage linked to the site’s event management.
OpenCVE Enrichment