CVE-2025-15473
Timetics < 1.0.52 - Unauthenticated Payment/Booking Status Update
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking" custom post type.
| Vendor | unknown |
| Product | timetics |
| Published | Mar 12, 2026 |
| Last Updated | Mar 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown timetics
Be the first to know when new medium vulnerabilities affecting unknown timetics are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Timetics
0 < 1.0.52
References
Credits
Khaled Alenazi (Nxploited) WPScan