CyberRota Analysis
AI-GeneratedThe Timetics WordPress plugin prior to version 1.0.57 is vulnerable as it allows unauthenticated users to create fully-approved bookings for paid appointments without requiring payment when using unrecognized payment methods. This flaw can lead to financial losses and unauthorized access to services. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.
Original NVD Description
The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment.