Impact
The Timetics WordPress plugin, versions 1.0.58 and earlier, contains an unauthenticated Cross‑Site Scripting vulnerability that allows the injection of arbitrary JavaScript into the output rendered to visitors. This flaw is catalogued as CWE‑79 and can be exploited without authentication, enabling attackers to execute code in the context of any user viewing affected pages.
Affected Systems
WordPress installations that utilize the Timetics plugin from Arraytics, specifically those running version 1.0.58 or earlier. The vendor recommends applying version 1.0.59 or newer to remove the vulnerability.
Risk and Exploitability
The flaw is scored 7.1 on the CVSS scale, indicating high severity. Its EPSS score is listed as < 1 %, showing a very low but non‑zero probability of exploitation, and it is not currently in the CISA KEV catalog. Attackers can leverage the unauthenticated vector by crafting a malicious URL or input that is reflected back into the page, causing arbitrary JavaScript to run in the victim’s browser.
OpenCVE Enrichment