Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics timetics allows Authentication Abuse.This issue affects Timetics: from n/a through <= 1.0.46.
Published: 2026-01-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an authentication bypass that permits an attacker to abuse authentication controls by following an alternate path or channel. This allows unauthorized users to masquerade as legitimate administrators or to gain elevated privileges, thereby exposing the site to compromised confidentiality, integrity, and availability. The weakness is classified as CWE-288, which relates to improper authorization enforcement.

Affected Systems

This issue affects the Arraytics Timetics WordPress plugin for versions up to and including 1.0.46. Any WordPress installation that has Timetics 1.0.46 or earlier is potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.8 denotes a high severity flaw, yet the EPSS score of < 1% indicates a very low current exploitation probability and the vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the plugin by navigating an alternative authentication route, potentially gaining unauthorized access to the admin interface. The lack of a published exploit does not guarantee safety, but the risk is mitigated by the low likelihood of exploitation and the availability of remediation.

Generated by OpenCVE AI on April 28, 2026 at 18:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Timetics plugin to version 1.0.47 or later.
  • Disable the Timetics plugin if it is not required for site functionality.
  • Implement additional access controls such as two‑factor authentication for WordPress administrator accounts.

Generated by OpenCVE AI on April 28, 2026 at 18:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 09 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Arraytics
Arraytics timetics
Wordpress
Wordpress wordpress
Vendors & Products Arraytics
Arraytics timetics
Wordpress
Wordpress wordpress

Thu, 08 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 08 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
Description Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics timetics allows Authentication Abuse.This issue affects Timetics: from n/a through <= 1.0.46.
Title WordPress Timetics plugin <= 1.0.46 - Broken Authentication vulnerability
Weaknesses CWE-288
References

Subscriptions

Arraytics Timetics
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:23.250Z

Reserved: 2025-12-15T09:59:40.762Z

Link: CVE-2025-67915

cve-icon Vulnrichment

Updated: 2026-01-08T14:56:22.316Z

cve-icon NVD

Status : Deferred

Published: 2026-01-08T10:15:50.343

Modified: 2026-04-27T18:16:48.463

Link: CVE-2025-67915

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T18:30:37Z

Weaknesses