Insecure Direct Object Reference in Timetable and Event Schedule by MotoPress Plugin for WordPress
CVE-2026-9228
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 May 2026
What is CVE-2026-9228?
The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference due to insufficient validation on a user-controlled key within the action_get_event_data function. This vulnerability allows authenticated users with contributor-level access or higher to enumerate timeslot IDs, thus exposing sensitive information such as the entire WP_Post object—including post content, excerpt, status, and author—for draft, pending, and private mp-event posts belonging to other users, along with their associated raw timeslot descriptions.
Affected Version(s)
Timetable and Event Schedule by MotoPress 0 <= 2.4.16