The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.0.25 via the save() due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to reset the emails and passwords of arbitrary user accounts, including administrators, which makes account takeover and privilege escalation possible.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Arraytics
Arraytics timetics |
|
CPEs | cpe:2.3:a:arraytics:timetics:*:*:*:*:*:*:*:* | |
Vendors & Products |
Arraytics
Arraytics timetics |
|
Metrics |
ssvc
|
Thu, 17 Oct 2024 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.0.25 via the save() due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to reset the emails and passwords of arbitrary user accounts, including administrators, which makes account takeover and privilege escalation possible. | |
Title | WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.25 - Insecure Direct Object Reference to Unauthenticated Arbitrary User Password/Email Reset/Account Takeover | |
Weaknesses | CWE-639 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-17T03:32:49.162Z
Updated: 2024-10-17T15:02:18.902Z
Reserved: 2024-09-26T20:13:08.336Z
Link: CVE-2024-9263
Vulnrichment
Updated: 2024-10-17T15:02:13.776Z
NVD
Status : Awaiting Analysis
Published: 2024-10-17T04:15:05.517
Modified: 2024-10-18T12:53:04.627
Link: CVE-2024-9263
Redhat
No data.