Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 03 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Timetics
Timetics timetics Wordpress Wordpress wordpress |
|
| Vendors & Products |
Timetics
Timetics timetics Wordpress Wordpress wordpress |
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members. | |
| Title | Timetics <= 1.0.61 - Staff+ Cross-Staff Appointment Modification via IDOR | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-02T14:57:38.546Z
Reserved: 2026-07-01T12:16:09.144Z
Link: CVE-2026-14326
Updated: 2026-09-02T14:41:42.830Z
Status : Received
Published: 2026-09-02T15:17:37.553
Modified: 2026-09-02T15:17:37.553
Link: CVE-2026-14326
No data.
OpenCVE Enrichment
Updated: 2026-09-03T14:15:06Z