Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Motopress

First CVE: Sep 13, 2021Active for: 5 yearsTotal CVEs: 24
18.4
VTI Score
Low

Motopress develops a focused suite of WordPress plugins and page-builder extensions, including Getwid, Timetable and Event Schedule, Hotel Booking Lite, and Jetblocks for Elementor, that extend content management and booking functionality for small-to-medium web publishers. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through application-layer weakness classes including cross-site scripting, missing authorization checks, cross-site request forgery, sensitive information exposure, and guessable CAPTCHA implementations. These patterns reflect the common pitfalls of plugin and theme development: insufficient input sanitization and output encoding in user-facing forms, weak or absent access controls on administrative features, and reliance on client-side or predictable security mechanisms. Defenders should audit deployed instances of these plugins for version and authorization configuration, as the exposure is particularly acute for publicly accessible booking and user-submission functionality. Live exploitation and severity counts are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Motopress over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 13, 2021
4 years ago
Most Recent CVE
Jan 30, 2025
543 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-5991CRITICAL
The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing u
Dec 26, 20239.840NOYES
CVE-2020-36840CRITICAL
The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function calle
Oct 16, 20249.828NONO
CVE-2023-1895CRITICAL
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versions up to, and including, 1.8.3
Jun 9, 20239.627NONO
CVE-2023-28498HIGH
Cross-Site Request Forgery (CSRF) vulnerability in MotoPress Hotel Booking Lite plugin <= 4.6.0 versions.
Nov 12, 20238.825NONO
CVE-2023-6042HIGH
Any unauthenticated user may send e-mail from the site with any title or content to the admin
Jan 8, 20247.523NONO
CVE-2022-2843MEDIUM
A vulnerability was found in MotoPress Timetable and Event Schedule. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /wp-admin/ad
Aug 16, 20226.122NONO
CVE-2021-24585MEDIUM
The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (along other less sensitive data) of the user related to the
Sep 20, 20216.522NONO
CVE-2022-2844MEDIUM
A vulnerability classified as problematic has been found in MotoPress Timetable and Event Schedule up to 1.4.06. This affects an unknown part of the file /wp/?cpmvc_id=1&cpmvc_do_a
Aug 16, 20226.121NONO
CVE-2021-24584MEDIUM
The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a timeslot, allowing any user with the edit_posts capability (contr
Sep 20, 20215.420NONO
CVE-2021-24544MEDIUM
The Responsive WordPress Slider WordPress plugin through 2.2.0 does not sanitise and escape some of the Slider options, allowing Cross-Site Scripting payloads to be set in them. Fu
Oct 25, 20215.419NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
79%
8%
13%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (95.8%)
High1 (4.2%)
Unknown0 (0.0%)
User Interaction
None11 (45.8%)
Unknown0 (0.0%)
Required13 (54.2%)
Privileges Required
Low12 (50.0%)
High2 (8.3%)
None10 (41.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.2% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Motopress.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Motopress — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Motopress's Products

View all 4 CNAs →

Top CWEs