CVE-2024-39630: WordPress Timetable and Event Schedule by MotoPress plugin <= 2.4.13 - PHP Object Injection vulnerability
Published Aug 1, 2024
·Updated
Deserialization of Untrusted Data vulnerability in MotoPress Timetable and Event Schedule allows Object Injection.This issue affects Timetable and Event Schedule: from n/a through 2.4.13.
Affected Software
2 affected components
MotoPress Timetable and Event Schedule<=2.4.13
MotoPress WordPress Timetable and Event Schedule<=2.4.13
Event History
Aug 1, 2024
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-39630?
CVE-2024-39630 is a high severity vulnerability due to its potential for object injection attacks.
2
How do I fix CVE-2024-39630?
To fix CVE-2024-39630, update the MotoPress Timetable and Event Schedule plugin to version 2.4.14 or later.
3
What versions are affected by CVE-2024-39630?
CVE-2024-39630 affects all versions of MotoPress Timetable and Event Schedule from n/a up to and including 2.4.13.
4
What is the impact of CVE-2024-39630?
The impact of CVE-2024-39630 includes potential remote code execution due to deserialization of untrusted data.
5
Who is impacted by CVE-2024-39630?
Users of MotoPress Timetable and Event Schedule versions 2.4.13 and below are impacted by CVE-2024-39630.