Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-30792 | The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function called via a nopriv AJAX action in versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to call that function and perform a wide variety of actions such as including random template, injecting malicious web scripts, and more. |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 30 Oct 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:motopress:timetable_and_event_schedule:*:*:*:*:*:wordpress:*:* |
Wed, 16 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Motopress
Motopress timetable And Event Schedule |
|
| CPEs | cpe:2.3:a:motopress:timetable_and_event_schedule:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Motopress
Motopress timetable And Event Schedule |
|
| Metrics |
ssvc
|
Wed, 16 Oct 2024 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function called via a nopriv AJAX action in versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to call that function and perform a wide variety of actions such as including random template, injecting malicious web scripts, and more. | |
| Title | Timetable and Event Schedule by MotoPress <= 2.3.8 - Missing Authorization | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:10:41.851Z
Reserved: 2024-10-15T18:44:28.632Z
Link: CVE-2020-36840
Updated: 2024-10-16T17:13:36.447Z
Status : Analyzed
Published: 2024-10-16T08:15:03.710
Modified: 2024-10-30T21:06:30.517
Link: CVE-2020-36840
No data.
OpenCVE Enrichment
No data.
EUVD