CVE-2024-11275

CVSS V2 None CVSS V3 None
Description
The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the /wp-json/timetics/v1/customers/ REST API endpoint in all versions up to, and including, 1.0.27. This makes it possible for authenticated attackers, with Timetics Customer access and above, to delete arbitrary users.
Overview
  • CVE ID
  • CVE-2024-11275
  • Assigner
  • Wordfence
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-12-13T08:24:52.066Z
  • Last Modified Date
  • 2024-12-13T21:15:20.452Z
History
Created Old Value New Value Data Type Notes
2024-12-14 13:56:55 Added to TrackCVE