SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-14322

MEDIUM · CVSS 5.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

The Timetics WordPress plugin prior to version 1.0.57 is vulnerable as it allows unauthenticated users to create fully-approved bookings for paid appointments without requiring payment when using unrecognized payment methods. This flaw can lead to financial losses and unauthorized access to services. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-14322
Severity
MEDIUM
CVSS
5.3
EPSS
0.18%
WordPress

Original NVD Description

The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment.