CVE-2024-3342: Timetable and Event Schedule by MotoPress <= 2.4.11 - Authenticated (Contributor+) SQL Injection
The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attribute of the 'mp-timetable' shortcode in all versions up to, and including, 2.4.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3342?
CVE-2024-3342 has a high severity rating due to its potential for SQL injection attacks.
How do I fix CVE-2024-3342?
To fix CVE-2024-3342, update the Timetable and Event Schedule plugin to version 2.4.12 or later.
Who is affected by CVE-2024-3342?
CVE-2024-3342 affects all versions of the Timetable and Event Schedule plugin for WordPress up to and including version 2.4.11.
What is SQL Injection in relation to CVE-2024-3342?
SQL Injection in CVE-2024-3342 refers to the vulnerability allowing attackers to execute arbitrary SQL code via user-supplied parameters.
What should users of the Timetable and Event Schedule plugin do regarding CVE-2024-3342?
Users should immediately update their Timetable and Event Schedule plugin to ensure protection against CVE-2024-3342.