Impact
The vulnerability is an unauthenticated broken access control flaw that allows an attacker to gain access to actions or data that should be restricted. The flaw stems from incorrect authorization checks in the Timetics plugin, exposing privileged functionality to users without proper authentication. This could lead to disclosure or modification of sensitive content, or execution of administrative actions within the WordPress site.
Affected Systems
Any WordPress installation running the Timetics plugin version 1.0.61 or earlier is affected. The vulnerability is tied to the Arraytics:Timetics product. There are no known additional affected components beyond the plugin itself.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, where an unauthenticated user can exploit the missing access controls without needing to bypass authentication. Given these metrics, the risk remains moderate, and a determined attacker could exploit the flaw if the vulnerability is present.
OpenCVE Enrichment