Extension WordPress

Vulnérabilités Timetics – Appointment Booking Calendar & Scheduling System

Cette page rassemble les failles publiées pour Timetics – Appointment Booking Calendar & Scheduling System, leurs plages de versions affectées et les correctifs signalés dans la base locale.

11Vulnérabilités
1Critiques
11Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Timetics – Appointment Booking Calendar & Scheduling System

11 fiches

CVE-2026-57674 Élevée · 7,2
Timetics – Appointment Booking Calendar & Scheduling System

Timetics – Appointment Booking Calendar & Scheduling System <= 1.0.58 – Unauthenticated Stored Cross-Site Scripting

The Timetics – Appointment Booking Calendar & Scheduling System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.58 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-1.0.58

Correctif

1.0.59

Publication

30/06/2026

CVE-2026-39432 Moyenne · 5,3
Timetics – Appointment Booking Calendar & Scheduling System

Timetics – Appointment Booking & Scheduling <= 1.0.53 – Missing Authorization

The Timetics – Appointment Booking & Scheduling plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.53. This makes it possible for unauthenticated…

Versions affectées

*-1.0.53

Correctif

1.0.54

Publication

07/04/2026

CVE-2025-15473 Moyenne · 5,3
Timetics – Appointment Booking Calendar & Scheduling System

Timetics – Appointment Booking Calendar & Scheduling System < 1.0.52 – Missing Authorization

The Timetics – Appointment Booking Calendar & Scheduling System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 1.0.52 (exclusive). This makes it possible for…

Versions affectées

[*, 1.0.52)

Correctif

1.0.52

Publication

12/03/2026

CVE-2025-5919 Moyenne · 6,5
Timetics – Appointment Booking Calendar & Scheduling System

Appointment Booking and Scheduling Calendar Plugin – WP Timetics <= 1.0.36 – Missing Authorization to Unauthenticated Booking Details View And Modification

The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the update and register_routes functions in all versions up…

Versions affectées

*-1.0.36

Correctif

1.0.37

Publication

05/01/2026

CVE-2025-67915 Moyenne · 5,3
Timetics – Appointment Booking Calendar & Scheduling System

Timetics <= 1.0.46 – Incorrect Authorization to Authenticated (Timetics Customer+) User Creation

The Appointment Booking Calendar – WP Timetics Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a insufficient capability check in the api-customer.php file in all versions up to, and including, 1.0.46. This makes it…

Versions affectées

*-1.0.46

Correctif

1.0.48

Publication

05/01/2026

CVE-2024-11275 Moyenne · 4,3
Timetics – Appointment Booking Calendar & Scheduling System

WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.27 – Missing Authorization to Authenticated (Subscriber+) Arbitrary User Deletion

The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the /wp-json/timetics/v1/customers/ REST API endpoint in all versions up to,…

Versions affectées

*-1.0.27

Correctif

1.0.28

Publication

12/12/2024

CVE-2024-9263 Critique · 9,8
Timetics – Appointment Booking Calendar & Scheduling System

WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.25 – Insecure Direct Object Reference to Unauthenticated Arbitrary User Password/Email Reset/Account Takeover

The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.0.25 via the save() due to…

Versions affectées

*-1.0.25

Correctif

1.0.26

Publication

16/10/2024

CVE-2024-1094 Élevée · 7,3
Timetics – Appointment Booking Calendar & Scheduling System

Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling Plugin <= 1.0.21 – Missing Authorization to Limited Privilege Escalation

The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the make_staff() function in all versions up to,…

Versions affectées

*-1.0.21

Correctif

1.0.22

Publication

13/06/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités