← WordPress Vulnerabilities
WordPress security by component

Timetics

Timetics is a WordPress component with 12 published CVE records in this archive. The latest tracked vulnerability was published Jul 22, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: timetics

CVE-2026-14322: Timetics can approve paid bookings without payment

Timetics before 1.0.57 trusts an unrecognised payment method when an unauthenticated visitor creates a booking. Instead of leaving the booking pending or unpaid, the vulnerable flow records it as fully approved, allowing priced appointments to be reserved without completing payment.

PublishedJul 22, 2026
Known safe version1.0.57
Safe version
Jul 22, 2026 CVE-2026-14322
Timetics can approve paid bookings without payment
Timetics before 1.0.57 trusts an unrecognised payment method when an unauthenticated visitor creates a booking. Instead of leaving the booking pending or unpaid, the vulnerable flow records it as fully approved, allowing priced appointments to be reserved without completing payment.
1.0.57
CVE5.3
NVDPending
Jul 02, 2026 CVE-2026-57674
Timetics: Cross-site scripting
Timetics is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.0.58.
1.0.59
CVE7.1
NVDPending
May 12, 2026 CVE-2026-39432
Timetics: A security weakness
Timetics is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.0.53.
1.0.54
CVE8.2
NVDPending
Mar 12, 2026 CVE-2025-15473
Timetics: A security weakness
Timetics is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jan 08, 2026 CVE-2025-67915
Timetics: Privilege escalation or authentication bypass
Timetics is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Jan 06, 2026 CVE-2025-5919
Appointment Booking and Scheduling Calendar Plugin – WP Timetics: A security weakness
Appointment Booking and Scheduling Calendar Plugin – WP Timetics is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Dec 18, 2025 CVE-2025-64268
Timetics: A security weakness
Timetics is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Mar 27, 2025 CVE-2025-30828
Timetics: A security weakness
Timetics is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 13, 2024 CVE-2024-11275
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin: A security weakness
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Nov 01, 2024 CVE-2024-43923
Timetics: A security weakness
Timetics is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD9.8
Nov 01, 2024 CVE-2024-37427
Timetics: A security weakness
Timetics is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Oct 17, 2024 CVE-2024-9263
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin: Privilege escalation or authentication bypass
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending