CVE-2025-12954: Timetable and Event Schedule by MotoPress < 2.4.16 - Contributor+ Event Disclosure via IDOR
The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a specific event when duplicating, leading to arbitrary event disclosure when to users with a role as low as Contributor.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12954?
CVE-2025-12954 is categorized as a medium severity vulnerability due to the potential for unauthorized access and data exposure.
How do I fix CVE-2025-12954?
To fix CVE-2025-12954, upgrade the Timetable and Event Schedule by MotoPress plugin to version 2.4.16 or later.
What type of access does CVE-2025-12954 compromise?
CVE-2025-12954 compromises access by allowing users with at least a Contributor role to duplicate events they do not have permission to see.
Which plugin is affected by CVE-2025-12954?
CVE-2025-12954 affects the Timetable and Event Schedule plugin by MotoPress.
What versions of the Timetable and Event Schedule are vulnerable to CVE-2025-12954?
Versions of the Timetable and Event Schedule plugin prior to 2.4.16 are vulnerable to CVE-2025-12954.