WordPress Timetics Plugin Vulnerability Allows Unauthenticated Booking Creation
CVE-2026-14322
Currently unrated
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-14322?
The Timetics WordPress plugin, prior to version 1.0.57, has a significant vulnerability that allows unauthorized users to create fully-approved bookings for paid appointments. This occurs due to the lack of enforcement of a pending or unpaid status for new bookings made through unsupported payment methods. As a result, individuals can exploit this flaw to bypass payment requirements and reserve appointments without making the corresponding payments.
Affected Version(s)
Timetics 0 < 1.0.57
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.