plugin

Timetics Vulnerabilities

13 known security issues reported for the Timetics WordPress plugin. Most recent disclosed Jul 1, 2026.

1 critical 2 high 10 medium

Running Timetics on your site? Check whether your installed version is affected.

Scan your site free

Timetics <= 1.0.56 - Missing Authorization to Unauthenticated Booking Approval

medium

The Timetics – Appointment Booking Calendar & Scheduling plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.56. This makes it possible for unauthenticated attackers to approve booking requests.

CVSS:
5.3
Affected:
up to 1.0.56
Fixed in:
1.0.57
Disclosed:
Jul 1, 2026

CVE-2026-14322 on NVD →

Timetics – Appointment Booking Calendar & Scheduling System <= 1.0.58 - Unauthenticated Stored Cross-Site Scripting

high

The Timetics – Appointment Booking Calendar & Scheduling System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.58 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...

CVSS:
7.2
Affected:
up to 1.0.58
Fixed in:
1.0.59
Disclosed:
Jun 30, 2026

CVE-2026-57674 on NVD →

Timetics – Appointment Booking & Scheduling <= 1.0.53 - Missing Authorization

medium

The Timetics – Appointment Booking & Scheduling plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.53. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.0.53
Fixed in:
1.0.54
Disclosed:
Apr 7, 2026

CVE-2026-39432 on NVD →

Timetics - Unauthenticated Payment/Booking Status Update vulnerability

medium

Unauthenticated Payment/Booking Status Update vulnerability

CVSS:
4.3
Affected:
up to 1.0.52
Fixed in:
1.0.52
Disclosed:
Mar 12, 2026

Timetics – Appointment Booking Calendar & Scheduling System < 1.0.52 - Missing Authorization

medium

The Timetics – Appointment Booking Calendar & Scheduling System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 1.0.52 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.0.52
Fixed in:
1.0.52
Disclosed:
Mar 12, 2026

CVE-2025-15473 on NVD →

Appointment Booking and Scheduling Calendar Plugin – WP Timetics <= 1.0.36 - Missing Authorization to Unauthenticated Booking Details View And Modification

medium

The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the update and register_routes functions in all versions up to, and including, 1.0.36. This makes it possible for unauthenticated a...

CVSS:
6.5
Affected:
up to 1.0.36
Fixed in:
1.0.37
Disclosed:
Jan 5, 2026

CVE-2025-5919 on NVD →

Timetics <= 1.0.46 - Incorrect Authorization to Authenticated (Timetics Customer+) User Creation

medium

The Appointment Booking Calendar – WP Timetics Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a insufficient capability check in the api-customer.php file in all versions up to, and including, 1.0.46. This makes it possible for authenticated attackers, with Timetics Customer-level acces...

CVSS:
5.3
Affected:
up to 1.0.46
Fixed in:
1.0.48
Disclosed:
Jan 5, 2026

CVE-2025-67915 on NVD →

Timetics <= 1.0.44 - Missing Authorization

medium

The Appointment Booking Calendar – WP Timetics Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.44. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.0.44
Fixed in:
1.0.45
Disclosed:
Nov 22, 2025

CVE-2025-64268 on NVD →

Timetics <= 1.0.29 - Missing Authorization

medium

The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.29. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.0.29
Fixed in:
1.0.30
Disclosed:
Mar 27, 2025

CVE-2025-30828 on NVD →

WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.27 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Deletion

medium

The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the /wp-json/timetics/v1/customers/ REST API endpoint in all versions up to, and including, 1.0.27. This makes it possible for authen...

CVSS:
4.3
Affected:
up to 1.0.27
Fixed in:
1.0.28
Disclosed:
Dec 12, 2024

CVE-2024-11275 on NVD →

WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.25 - Insecure Direct Object Reference to Unauthenticated Arbitrary User Password/Email Reset/Account Takeover

critical

The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.0.25 via the save() due to missing validation on a user controlled key. This make...

CVSS:
9.8
Affected:
up to 1.0.25
Fixed in:
1.0.26
Disclosed:
Oct 16, 2024

CVE-2024-9263 on NVD →

Timetics <= 1.0.23 - Authorization Bypass

medium

The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized booking in all versions up to, and including, 1.0.23. This is due to the plugin not properly validating if a user is authorized to make a booking. This makes it possible for unauthent...

CVSS:
5.3
Affected:
up to 1.0.23
Fixed in:
1.0.24
Disclosed:
Aug 26, 2024

CVE-2024-43923 on NVD →

Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling Plugin <= 1.0.21 - Missing Authorization to Limited Privilege Escalation

high

The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the make_staff() function in all versions up to, and including, 1.0.21. This makes it possible for unauthentica...

CVSS:
7.3
Affected:
up to 1.0.21
Fixed in:
1.0.22
Disclosed:
Jun 13, 2024

CVE-2024-1094 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database