CVE-2025-15473
MEDIUM
4.3
Our Analysis: esv
Our model has classified this vulnerability as relevant to esv Systems, helping your team prioritize efforts effectively.
Published Date
March 12, 2026
Last Modified
March 12, 2026
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Description
The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking" custom post type.