CVE-2026-14326: Timetics <= 1.0.61 - Staff+ Cross-Staff Appointment Modification via IDOR
The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Timetics WordPress pluginto a version that resolves this vulnerability.Fixed in 1.0.61
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must already have an account with the Timetics custom staff role. The issue is exposed through the plugin's REST API and does not require user interaction.
What can a malicious staff user do?
They can modify, disable, or take over appointments that belong to other staff members. The available data indicates impacts to appointment integrity and availability, not confidentiality.
How can administrators determine whether they may be affected?
Sites using Timetics version 1.0.61 or earlier may be affected, particularly where multiple staff accounts can access the plugin. Review appointment changes and REST API activity for staff accounts modifying appointments assigned to other staff members.