VYPR

Mp Timetable

by WordPress

CVEs (3)

  • CVE-2024-3342CriApr 27, 2024
    risk 0.57cvss 9.9epss 0.00

    The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attribute of the 'mp-timetable' shortcode in all versions up to, and including, 2.4.11 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2024-39630MedAug 1, 2024
    risk 0.36cvss 5.5epss 0.00

    Deserialization of Untrusted Data vulnerability in MotoPress Timetable and Event Schedule allows Object Injection.This issue affects Timetable and Event Schedule: from n/a through 2.4.13.

  • CVE-2026-9228MedMay 28, 2026
    risk 0.28cvss 4.3epss

    The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the action_get_event_data due to missing validation on a user controlled key. This makes it possible for…