The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the update and register_routes functions in all versions up to, and including, 1.0.36. This makes it possible for unauthenticated attackers to view and modify booking details.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-06 09:15
Updated : 2026-01-08 18:09
NVD link : CVE-2025-5919
Mitre link : CVE-2025-5919
CVE.ORG link : CVE-2025-5919
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
