WordPress Timetics plugin <= 1.0.23 - Broken Access Control vulnerability
CVE-2024-43923
9.8CRITICAL
Summary
The Arraytics Timetics product is impacted by a missing authorization vulnerability, which permits unauthorized users to access functionalities that should be restricted. This flaw arises from inadequate enforcement of access control lists (ACLs), allowing potential exploitation by malicious entities. The vulnerability affects all Timetics versions from n/a to 1.0.23, highlighting the need for immediate attention to safeguard sensitive functionalities from unauthorized access.
Affected Version(s)
Timetics <= 1.0.23
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Manab Jyoti Dowarah (Patchstack Alliance)