WordPress Timetics plugin <= 1.0.23 - Broken Access Control vulnerability
CVE-2024-43923

9.8CRITICAL

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
1 November 2024

Summary

The Arraytics Timetics product is impacted by a missing authorization vulnerability, which permits unauthorized users to access functionalities that should be restricted. This flaw arises from inadequate enforcement of access control lists (ACLs), allowing potential exploitation by malicious entities. The vulnerability affects all Timetics versions from n/a to 1.0.23, highlighting the need for immediate attention to safeguard sensitive functionalities from unauthorized access.

Affected Version(s)

Timetics <= 1.0.23

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Manab Jyoti Dowarah (Patchstack Alliance)
.