CVE-2026-84215: WordPress Timetics plugin <= 1.0.61 - Broken Access Control vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.
Affected Software
1 affected component
WordPress Timetics plugin<=1.0.61
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Timetics pluginto a version that resolves this vulnerability.Fixed in 1.0.62
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other credentials to attempt exploitation over the network.
2
What security impact is reported?
The reported CVSS vector indicates low integrity and availability impact, with no confidentiality impact. The issue is rated medium severity with a score of 6.5.
3
Which installations should be considered affected?
WordPress sites using the Timetics plugin version 1.0.61 or earlier should be considered affected based on the reported version range.