WordPress security by component
Timetics
Plugin description
Timetics is a WordPress component with 12 published CVE records in this archive. The latest tracked vulnerability was published Jul 22, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
timeticsLatest vulnerability
CVE-2026-14322: Timetics can approve paid bookings without payment
Timetics before 1.0.57 trusts an unrecognised payment method when an unauthenticated visitor creates a booking. Instead of leaving the booking pending or unpaid, the vulnerable flow records it as fully approved, allowing priced appointments to be reserved without completing payment.
| Safe version |
|
||
|---|---|---|---|
| Jul 22, 2026 |
CVE-2026-14322
Timetics can approve paid bookings without payment
Timetics before 1.0.57 trusts an unrecognised payment method when an unauthenticated visitor creates a booking. Instead of leaving the booking pending or unpaid, the vulnerable flow records it as fully approved, allowing priced appointments to be reserved without completing payment.
|
1.0.57 |
CVE5.3
NVDPending
|
| Jul 02, 2026 |
CVE-2026-57674
Timetics: Cross-site scripting
Timetics is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.0.58.
|
1.0.59 |
CVE7.1
NVDPending
|
| May 12, 2026 |
CVE-2026-39432
Timetics: A security weakness
Timetics is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.0.53.
|
1.0.54 |
CVE8.2
NVDPending
|
| Mar 12, 2026 |
CVE-2025-15473
Timetics: A security weakness
Timetics is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jan 08, 2026 |
CVE-2025-67915
Timetics: Privilege escalation or authentication bypass
Timetics is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Jan 06, 2026 |
CVE-2025-5919
Appointment Booking and Scheduling Calendar Plugin – WP Timetics: A security weakness
Appointment Booking and Scheduling Calendar Plugin – WP Timetics is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 18, 2025 |
CVE-2025-64268
Timetics: A security weakness
Timetics is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Mar 27, 2025 |
CVE-2025-30828
Timetics: A security weakness
Timetics is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 13, 2024 |
CVE-2024-11275
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin: A security weakness
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Nov 01, 2024 |
CVE-2024-43923
Timetics: A security weakness
Timetics is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD9.8
|
| Nov 01, 2024 |
CVE-2024-37427
Timetics: A security weakness
Timetics is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Oct 17, 2024 |
CVE-2024-9263
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin: Privilege escalation or authentication bypass
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVDPending
|