Home Embedded Vulns General Vulns

CVE-2025-15473

MEDIUM 4.3

Our Analysis: esv

Our model has classified this vulnerability as relevant to esv Systems, helping your team prioritize efforts effectively.

Published Date March 12, 2026
Last Modified March 12, 2026
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Description

The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking" custom post type.

Potentially Affected Vendors