cleantalk
Vulnerabilities and Security Researches

Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling, CVE-2024-11275

CVE, Research URL

CVE-2024-11275

Published on
Dec 13, 2024
Research Description
The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the /wp-json/timetics/v1/customers/ REST API endpoint in all versions up to, and including, 1.0.27. This makes it possible for authenticated attackers, with Timetics Customer access and above, to delete arbitrary users.
Affected versions
max 1.0.28.
Status
vulnerable