Loading market data...
← Back to CVE feed

CVE-2026-14326

LOW CVSS 3.8 View on NVD ↗

Description

The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Published: Sep 02, 2026 15:17 UTC Modified: Sep 02, 2026 15:17 UTC