CVE-2020-36840

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function called via a nopriv AJAX action in versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to call that function and perform a wide variety of actions such as including random template, injecting malicious web scripts, and more.
Configurations

Configuration 1 (hide)

cpe:2.3:a:motopress:timetable_and_event_schedule:*:*:*:*:*:wordpress:*:*

History

30 Oct 2024, 21:06

Type Values Removed Values Added
CPE cpe:2.3:a:motopress:timetable_and_event_schedule:*:*:*:*:*:wordpress:*:*
First Time Motopress timetable And Event Schedule
Motopress
References () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2288592%40mp-timetable&new=2288592%40mp-timetable&sfp_email=&sfph_mail= - () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2288592%40mp-timetable&new=2288592%40mp-timetable&sfp_email=&sfph_mail= - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/988d7b33-f985-4d22-a2db-3922002fcecb?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/988d7b33-f985-4d22-a2db-3922002fcecb?source=cve - Third Party Advisory
CVSS v2 : unknown
v3 : 7.3
v2 : unknown
v3 : 9.8

16 Oct 2024, 16:38

Type Values Removed Values Added
Summary
  • (es) El complemento Timetable and Event Schedule de MotoPress para WordPress es vulnerable a la omisión de autorización debido a una verificación de capacidad faltante en la función wp_ajax_route_url() llamada a través de una acción AJAX nopriv en versiones hasta la 2.3.8 incluida. Esto hace posible que atacantes no autenticados llamen a esa función y realicen una amplia variedad de acciones, como incluir una plantilla aleatoria, inyectar scripts web maliciosos y más.

16 Oct 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-16 08:15

Updated : 2024-10-30 21:06


NVD link : CVE-2020-36840

Mitre link : CVE-2020-36840

CVE.ORG link : CVE-2020-36840


JSON object : View

Products Affected

motopress

  • timetable_and_event_schedule
CWE
CWE-862

Missing Authorization