CVE-2026-14322 PUBLISHED

Timetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payment_method

Assigner: WPScan
Reserved: 01.07.2026 Published: 22.07.2026 Updated: 22.07.2026

The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment.

Product Status

Vendor Unknown
Product Timetics
Versions Default: unaffected
  • affected from 0 to 1.0.57 (excl.)

Credits

  • md. minaruzzaman shovon finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE