Unauthenticated Access Control Flaw in Timetics Plugin by WordPress
CVE-2026-84215

6.5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-84215?

The Timetics plugin for WordPress has a severe issue with unauthenticated broken access control in versions 1.0.61 and prior. This vulnerability potentially allows attackers to gain unauthorized access to sensitive functionality, leading to exploitation without proper authentication. Site owners are advised to take immediate action by updating to secure versions and reviewing access settings to prevent potential attacks.

Affected Version(s)

Timetics <= 1.0.61

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NamDang | Patchstack Bug Bounty Program
.