CVE-2026-14322
Description
The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Unknown | Timetics | — | 0 < 1.0.57 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-284 Improper Access Control |