PT-2021-16099 · WordPress · Timetable/Event Schedule

·

CVE-2021-24583

·

Published

2021-09-20

·

Updated

2022-10-25

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Timetable and Event Schedule WordPress plugin versions prior to 2.4.2
Description The issue concerns a lack of proper access control and the absence of a CSRF check, allowing any user with the edit posts capability to delete arbitrary timeslots from any events. This can be exploited via CSRF against a logged-in user with such capability.
Recommendations For versions prior to 2.4.2, update to version 2.4.2 or later to resolve the issue. As a temporary workaround, consider restricting the edit posts capability to trusted users only until the update can be applied.

Exploit

Fix

Improper Access Control

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24583

Affected Products

Timetable/Event Schedule