← Back

Motopress

motopress

23 CVEs • 7 products

Products (7)

Click to collapse
Toggle

CVEs (23)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Motopress
1Timetable And Event Schedule
Nov 21, 2024
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a timeslot, allowing any user with the edit_posts capability (contributor+) to update arbitrary timeslot fr...Show more
The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a timeslot, allowing any user with the edit_posts capability (contributor+) to update arbitrary timeslot from any events. Furthermore, no CSRF check is in place as well, allowing such attack to be perform via CSRF against a logged in with such capability. In versions before 2.3.19, the lack of sanitisation and escaping in some of the fields, like the descritption could also lead to Stored XSS issuesShow less
1Motopress
1Timetable And Event Schedule
Nov 21, 2024
Sep 20, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a timeslot, allowing any user with the edit_posts capability (contributor+) to delete arbitrary timeslot fr...Show more
The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a timeslot, allowing any user with the edit_posts capability (contributor+) to delete arbitrary timeslot from any events. Furthermore, no CSRF check is in place as well, allowing such attack to be performed via CSRF against a logged in with such capabilityShow less
1Motopress
1Timetable And Event Schedule
Nov 21, 2024
Sep 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privilege users such as author to perform XSS attacks against frontend and back...Show more
The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privilege users such as author to perform XSS attacks against frontend and backend users when viewing the related event/sShow less