CVE-2025-12954: Unknown Timetable And Event Schedule By Motopress

Low severity, CVSS 2.7. EPSS: 0.2% chance of exploitation in the next 30 days.

The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a specific event when duplicating, leading to arbitrary event disclosure when to users with a role as low as Contributor.

Affected products

  • Unknown Timetable And Event Schedule By Motopress: before 2.4.16 (fixed in 2.4.16)

Published 2025-12-03. Last modified 2026-06-17.