CVE-2021-24583: Timetable and Event Schedule by MotoPress < 2.4.2 - Unauthorised Event TimeSlot Deletion
The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a timeslot, allowing any user with the editposts capability (contributor+) to delete arbitrary timeslot from any events. Furthermore, no CSRF check is in place as well, allowing such attack to be performed via CSRF against a logged in with such capability
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24583?
CVE-2021-24583 is a vulnerability in the Timetable and Event Schedule WordPress plugin before version 2.4.2 that allows users with the edit_posts capability to delete arbitrary timeslots from any events.
What is the severity of CVE-2021-24583?
The severity of CVE-2021-24583 is medium with a CVSS score of 4.3.
How does CVE-2021-24583 affect the Timetable and Event Schedule plugin?
CVE-2021-24583 allows users with the edit_posts capability to delete arbitrary timeslots from any events in the Timetable and Event Schedule plugin.
What is the Common Weakness Enumeration (CWE) associated with CVE-2021-24583?
The Common Weakness Enumeration (CWE) associated with CVE-2021-24583 is CWE-352 (Cross-Site Request Forgery) and CWE-284 (Improper Access Control).
Is there a fix available for CVE-2021-24583?
Yes, a fix is available for CVE-2021-24583. Users should update the Timetable and Event Schedule plugin to version 2.4.2 or later to mitigate the vulnerability.