PT-2024-10850 · Motopress · The Timetable/Event Schedule By Motopress
Ram
+1
·
Published
2024-10-16
·
Updated
2024-10-30
·
CVE-2020-36840
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Timetable and Event Schedule by MotoPress plugin for WordPress versions up to, and including, 2.3.8
Description
The issue is related to a missing capability check on the
wp ajax route url() function called via a nopriv AJAX action. This allows unauthenticated attackers to call the function and perform various actions, including including random templates and injecting malicious web scripts.Recommendations
For versions up to, and including, 2.3.8, update to the latest release to mitigate risks. As a temporary workaround, consider restricting access to the
wp ajax route url() function until a patch is available. Additionally, ensure that all plugins are up-to-date to minimize the risk of exploitation.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Timetable/Event Schedule By Motopress