CVE-2026-14326

The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 15:17

Updated : 2026-09-03 17:50


NVD link : CVE-2026-14326

Mitre link : CVE-2026-14326

CVE.ORG link : CVE-2026-14326


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key