PoC Index82,564 CVEs with PoCs

CVE-2026-14326

Timetics <= 1.0.61 - Staff+ Cross-Staff Appointment Modification via IDOR

LOW 3.8EPSS 0.2%

The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members.

Affected
Timetics
CVSS v3.1 WPSCAN
3.8 LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
EPSS
0.23% chance of exploitation in the next 30 days, 14th percentile
Published
2026-09-02

Proof-of-concept exploits (1)

References