CVE-2026-39432: WordPress Timetics plugin <= 1.0.53 - Broken Access Control vulnerability
Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Timetics: from n/a through 1.0.53.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39432?
CVE-2026-39432 is categorized as a broken access control vulnerability which can lead to unauthorized access to sensitive data.
How do I fix CVE-2026-39432?
To mitigate CVE-2026-39432, update the Timetics plugin to the latest version above 1.0.53 which addresses the access control issues.
What are the potential impacts of exploiting CVE-2026-39432?
Exploiting CVE-2026-39432 can allow attackers to bypass security measures, leading to unauthorized access or manipulation of data.
Which versions of Timetics are affected by CVE-2026-39432?
CVE-2026-39432 affects all versions of Timetics up to and including version 1.0.53.
Who is impacted by CVE-2026-39432?
Any WordPress site using the Timetics plugin version 1.0.53 or earlier is at risk from CVE-2026-39432.