CVE-2026-14322
Deferred Deferred - Pending Action

Unauthenticated Booking Approval in Timetics WordPress Plugin

Vulnerability report for CVE-2026-14322, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-22

Assigner: WPScan

Description

The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-22
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-10
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
timetics wordpress_plugin to 1.0.57 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Timetics WordPress plugin before version 1.0.57 has a flaw where it does not check if bookings made through non-recognized payment methods should be pending or unpaid. This allows unauthenticated users to create fully approved bookings for paid appointments without making any payment by sending a single POST request to the plugin's API.

Detection Guidance

Check if your Timetics WordPress plugin version is below 1.0.57. Inspect server logs for unauthenticated POST requests to the plugin's API endpoint creating bookings without payment. Look for unexpected approved bookings in the system.

Impact Analysis

This vulnerability could allow attackers to book paid appointments without paying, leading to lost revenue, overbooked schedules, and potential disruption of services. It may also trigger unnecessary confirmations, emails, and calendar events for unpaid bookings.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by allowing unauthorized creation of appointments without payment verification. Unpaid bookings may expose personal data in confirmation emails or calendar events, violating data protection requirements for secure handling of sensitive information.

Mitigation Strategies

Update the Timetics WordPress plugin to version 1.0.57 or later immediately. Review all recent bookings for unauthorized approved appointments and cancel any suspicious ones. Monitor the plugin's API endpoint for unusual POST requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14322. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart