← Back

CVE-2026-14326

nvd nist
Published: Sep 2, 2026Modified: Sep 3, 2026Deferred

JSON object

Loading...
3.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Exploitability: 1.2 / Impact: 2.5
Source: contact@wpscan.com (Secondary)

Description

The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members.

Timeline

No history available yet.