Impact
The Timetics plugin for WordPress fails to enforce per-object ownership when appointments are updated through its REST API. Users with the custom staff role can modify, disable, or take over appointments that belong to other staff members, compromising the integrity and availability of appointment data.
Affected Systems
The vulnerability affects Timetics WordPress plugin versions 1.0.61 and earlier. No other vendors or product versions are listed.
Risk and Exploitability
The CVSS score of 3.8 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves authenticated staff users sending crafted REST API requests to modify appointments belonging to other staff members. No additional prerequisites beyond possessing the staff role are stated in the description.
OpenCVE Enrichment