Executive brief
Timetics is a WordPress plugin that allows businesses to manage staff appointments and scheduling. The plugin fails to properly verify that staff members can only modify their own appointments, allowing any staff member to alter, disable, or take over appointments belonging to other staff members through its REST API.
Technical details
This is an Insecure Direct Object Reference (IDOR) vulnerability in the Timetics REST API appointments endpoint. The vulnerable component is the PUT /wp-json/timetics/v1/appointments/{id} endpoint, which does not enforce per-object ownership checks when updating appointment records. An authenticated user with the custom timetics-staff role can modify any appointment ID by sending a REST request with their valid WordPress nonce, bypassing authorization controls. An attacker can modify appointment details (name, visibility, duration, capacity) and transfer ownership (author field) to themselves. The vulnerability is fixed in version 1.0.62; all versions through 1.0.61 are affected.
Affected products
- Timetics Timetics through 1.0.61
Timeline
- 2026-08-26: disclosed
- 2026-08-26: patched: Fixed in version 1.0.62
- 2026-09-02: advisory
- 2026-09-21: other: Last updated in vulnerability database