CVE-2020-36840: Timetable and Event Schedule by MotoPress <= 2.3.8 - Missing Authorization
The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpajaxrouteurl() function called via a nopriv AJAX action in versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to call that function and perform a wide variety of actions such as including random template, injecting malicious web scripts, and more.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36840?
CVE-2020-36840 has a medium severity rating as it allows unauthorized access through an authorization bypass in the WordPress plugin.
How do I fix CVE-2020-36840?
To fix CVE-2020-36840, update the Timetable and Event Schedule by MotoPress plugin to version 2.3.9 or higher.
Who is affected by CVE-2020-36840?
Users of the Timetable and Event Schedule by MotoPress plugin for WordPress versions up to 2.3.8 are affected by CVE-2020-36840.
What types of attacks can CVE-2020-36840 enable?
CVE-2020-36840 can enable attackers to perform unauthorized actions by bypassing capability checks in the affected plugin.
Is there a known exploit for CVE-2020-36840?
Yes, CVE-2020-36840 can potentially be exploited by unauthorized users to manipulate the event scheduling without proper permissions.