Extension WordPress
Vulnérabilités Timetics – Appointment Booking Calendar & Scheduling System
Cette page rassemble les failles publiées pour Timetics – Appointment Booking Calendar & Scheduling System, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Timetics – Appointment Booking Calendar & Scheduling System
11 fiches
Timetics – Appointment Booking Calendar & Scheduling System <= 1.0.58 – Unauthenticated Stored Cross-Site Scripting
The Timetics – Appointment Booking Calendar & Scheduling System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.58 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.0.58
1.0.59
30/06/2026
Timetics – Appointment Booking & Scheduling <= 1.0.53 – Missing Authorization
The Timetics – Appointment Booking & Scheduling plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.53. This makes it possible for unauthenticated…
*-1.0.53
1.0.54
07/04/2026
Timetics – Appointment Booking Calendar & Scheduling System < 1.0.52 – Missing Authorization
The Timetics – Appointment Booking Calendar & Scheduling System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 1.0.52 (exclusive). This makes it possible for…
[*, 1.0.52)
1.0.52
12/03/2026
Appointment Booking and Scheduling Calendar Plugin – WP Timetics <= 1.0.36 – Missing Authorization to Unauthenticated Booking Details View And Modification
The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the update and register_routes functions in all versions up…
*-1.0.36
1.0.37
05/01/2026
Timetics <= 1.0.46 – Incorrect Authorization to Authenticated (Timetics Customer+) User Creation
The Appointment Booking Calendar – WP Timetics Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a insufficient capability check in the api-customer.php file in all versions up to, and including, 1.0.46. This makes it…
*-1.0.46
1.0.48
05/01/2026
Timetics <= 1.0.44 – Missing Authorization
The Appointment Booking Calendar – WP Timetics Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.44. This makes it possible…
*-1.0.44
1.0.45
22/11/2025
Timetics <= 1.0.29 – Missing Authorization
The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.29. This makes it…
*-1.0.29
1.0.30
27/03/2025
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.27 – Missing Authorization to Authenticated (Subscriber+) Arbitrary User Deletion
The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the /wp-json/timetics/v1/customers/ REST API endpoint in all versions up to,…
*-1.0.27
1.0.28
12/12/2024
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.25 – Insecure Direct Object Reference to Unauthenticated Arbitrary User Password/Email Reset/Account Takeover
The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.0.25 via the save() due to…
*-1.0.25
1.0.26
16/10/2024
Timetics <= 1.0.23 – Authorization Bypass
The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized booking in all versions up to, and including, 1.0.23. This is due to the plugin not properly validating if a…
*-1.0.23
1.0.24
26/08/2024
Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling Plugin <= 1.0.21 – Missing Authorization to Limited Privilege Escalation
The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the make_staff() function in all versions up to,…
*-1.0.21
1.0.22
13/06/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.