CVE-2024-9263
17.10.2024, 04:15
The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.0.25 via the save() due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to reset the emails and passwords of arbitrary user accounts, including administrators, which makes account takeover and privilege escalation possible.Enginsight
| Vendor | Product | Version |
|---|---|---|
| arraytics | timetics | 𝑥 ≤ 1.0.25 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References