SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-14326

LOW · CVSS 3.8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Timetics WordPress plugin, up to version 1.0.61, is vulnerable due to a lack of per-object ownership enforcement in its REST API, enabling users with custom staff roles to alter or take control of appointments assigned to other staff members. This could lead to unauthorized modifications and potential data breaches within appointment management. WordPress site administrators using this plugin should prioritize applying updates or implementing access controls to mitigate the risk.

CVE
CVE-2026-14326
Severity
LOW
CVSS
3.8
EPSS
0.23%
WordPress

Original NVD Description

The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members.