Impact
The Timetics WordPress plugin, in versions before 1.0.57, does not validate that a new booking submitted with a payment_method not listed in the configured payment gateways is pending or unpaid. As a result, an unauthenticated user can submit a booking request with an arbitrary payment_method value and receive an immediately approved appointment that the site owner has not yet collected payment for. This flaw is an authorization weakness (CWE-284) that can lead to a loss of revenue and scheduling conflicts.
Affected Systems
Any WordPress site that has installed the Timetics plugin version 1.0.56 or earlier is affected. The vulnerability applies solely to the plugin itself, not to the core WordPress platform. Site administrators should verify the currently installed Timetics version and update if necessary.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. The EPSS score of less than 1 percent reflects a low probability of exploitation at present, and the vulnerability is not listed in CISA's KEV catalog. Attackers can exploit the flaw by sending a crafted request to the public booking form that includes an arbitrary payment_method parameter; no authentication is required, so the prerequisites for exploitation are minimal while the impact remains the creation of unpaid, fully approved appointments.
OpenCVE Enrichment