Timetable and Event Schedule by MotoPress <= 2.4.1 - Unauthorised Event TimeSlot Update

2021-08-23 00:00
dc11

Strategic Overview

Status
Patched in 2.4.2
Affected Version<= 2.4.1
CVSS6.4Medium
CVECVE-2021-24584
View all Timetable and Event Schedule by MotoPress vulnerabilities

Vulnerability Overview

The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a timeslot, allowing any user with the edit_posts capability (contributor+) to update arbitrary timeslot from any events. Furthermore, no CSRF check is in place as well, allowing such attack to be perform via CSRF against a logged in with such capability. In versions before 2.3.19, the lack of sanitisation and escaping in some of the fields, like the descritption could also lead to Stored XSS issues

Technical Analysis

REMEDIATION: Update to version 2.4.2, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C