Sceawere

Vulnerability Detail

CVE-2026-97304UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Timetics Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
2h ago
Vendor
Arraytics
Product
Timetics
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through 1.0.63.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-05T19:17:27.390Z",
  "pubdate": "2026-10-05T19:17:27.390Z",
  "executiveSummary": "The vulnerability is a Missing Authorization flaw identified in the Arraytics Timetics plugin for WordPress, specifically affecting versions from n/a through 1.0.63.\nThe issue stems from incorrectly configured access control security levels, which fail to properly validate the authorization status of users performing sensitive operations.\nAn unauthenticated or low-privileged attacker can exploit this security gap to perform actions intended only for higher-privileged accounts or administrators.\nThe impact includes unauthorized access to system features, potential data manipulation, and the subversion of business logic within the application.\nBecause the vulnerability exists at the access control layer, it does not require complex pre-conditions, making the exploitation process straightforward for remote attackers.\nThe risk implication is significant as it compromises the integrity and confidentiality of the Timetics scheduling platform, potentially leading to unauthorized modification of bookings, appointments, or plugin configurations.",
  "technicalDetails": "The core of the vulnerability lies in improper implementation of authorization checks within the Timetics plugin's request handling logic. The application fails to verify the user's role or capabilities before executing sensitive function calls, effectively ignoring the standard WordPress access control mechanisms.\nThis flaw allows a remote attacker to trigger server-side functions by sending specially crafted HTTP requests to the plugin's endpoints. Because the access control security levels are incorrectly configured, the plugin assumes that the requester has sufficient authorization, bypassing the necessary security checks entirely.\nThe attack flow involves an adversary identifying the accessible plugin endpoints that handle administrative or privileged operations. Once identified, the attacker crafts a request—typically via POST or GET—that targets these endpoints. Since the underlying codebase lacks a robust 'current_user_can()' check or an equivalent authorization verification, the server executes the requested action without confirming the identity or the permissions of the requester.\nSpecifically, the vulnerable component resides within the plugin's action handlers, where authorization should have been enforced prior to logic execution. In versions 1.0.63 and earlier, the absence of these mandatory security wrappers allows for the unauthorized invocation of backend functions.\nSuccessful exploitation requires no prior authentication, as the vulnerable functions are exposed to the public network. Post-exploitation, an attacker can manipulate application data, delete or modify appointments, or potentially reconfigure plugin settings, depending on the breadth of the functionality exposed through the inadequately protected endpoints.\nThe vulnerability is characterized by a failure to perform adequate input or request validation concerning the user's privilege level. By exploiting this, an adversary gains an elevated level of control over the plugin's operational environment, effectively circumventing the intended security model established by the Timetics framework."
}
CVE-2026-97304: Timetics Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere