The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-02 15:17
Updated : 2026-09-03 17:50
NVD link : CVE-2026-14326
Mitre link : CVE-2026-14326
CVE.ORG link : CVE-2026-14326
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
