CVE-2026-14322
Timetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payment_method
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment.
| Vendor | unknown |
| Product | timetics |
| Published | Jul 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown timetics
Be the first to know when new unknown vulnerabilities affecting unknown timetics are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Timetics
0 < 1.0.57
References
Credits
md. minaruzzaman shovon WPScan