Motopress develops a focused suite of WordPress plugins and page-builder extensions, including Getwid, Timetable and Event Schedule, Hotel Booking Lite, and Jetblocks for Elementor, that extend content management and booking functionality for small-to-medium web publishers. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through application-layer weakness classes including cross-site scripting, missing authorization checks, cross-site request forgery, sensitive information exposure, and guessable CAPTCHA implementations. These patterns reflect the common pitfalls of plugin and theme development: insufficient input sanitization and output encoding in user-facing forms, weak or absent access controls on administrative features, and reliance on client-side or predictable security mechanisms. Defenders should audit deployed instances of these plugins for version and authorization configuration, as the exposure is particularly acute for publicly accessible booking and user-submission functionality. Live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Motopress over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-5991CRITICAL The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing u | Dec 26, 2023 | 9.8 | 40 | NO | YES |
CVE-2020-36840CRITICAL The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function calle | Oct 16, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-1895CRITICAL The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versions up to, and including, 1.8.3 | Jun 9, 2023 | 9.6 | 27 | NO | NO |
CVE-2023-28498HIGH Cross-Site Request Forgery (CSRF) vulnerability in MotoPress Hotel Booking Lite plugin <= 4.6.0 versions. | Nov 12, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-6042HIGH Any unauthenticated user may send e-mail from the site with any title or content to the admin | Jan 8, 2024 | 7.5 | 23 | NO | NO |
CVE-2022-2843MEDIUM A vulnerability was found in MotoPress Timetable and Event Schedule. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /wp-admin/ad | Aug 16, 2022 | 6.1 | 22 | NO | NO |
CVE-2021-24585MEDIUM The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (along other less sensitive data) of the user related to the | Sep 20, 2021 | 6.5 | 22 | NO | NO |
CVE-2022-2844MEDIUM A vulnerability classified as problematic has been found in MotoPress Timetable and Event Schedule up to 1.4.06. This affects an unknown part of the file /wp/?cpmvc_id=1&cpmvc_do_a | Aug 16, 2022 | 6.1 | 21 | NO | NO |
CVE-2021-24584MEDIUM The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a timeslot, allowing any user with the edit_posts capability (contr | Sep 20, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-24544MEDIUM The Responsive WordPress Slider WordPress plugin through 2.2.0 does not sanitise and escape some of the Slider options, allowing Cross-Site Scripting payloads to be set in them. Fu | Oct 25, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Motopress.
Media articles that mention a CVE ID that affects a product developed by Motopress — matched by CVE ID, not by vendor name.