CVE-2025-15473 - Timetics < 1.0.52 - Unauthenticated Payment/Booking Status Update
CVE ID :CVE-2025-15473
Published : March 12, 2026, 6:16 a.m. | 3 hours, 12 minutes ago
Description :The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking" custom post type.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : March 12, 2026, 6:16 a.m. | 3 hours, 12 minutes ago
Description :The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking" custom post type.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...