Junglewise Threat Intelligence

CVE-2026-39432: Arraytics Timetics missing authorization in access control

CVE-2026-39432 · Severity: high · CVSS 8.2 · Published 2026-05-12

Technologies: Arraytics Timetics. Vendors: Arraytics.

Executive brief

Arraytics Timetics is a WordPress plugin used for appointment booking and scheduling. A security flaw in the plugin allows unauthorized individuals to bypass access controls and perform actions or view data they should not be able to see. This could lead to the exposure of sensitive customer information or unauthorized changes to booking configurations. Organizations using this plugin should update to version 1.0.54 immediately to prevent potential data breaches.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Arraytics Timetics plugin for WordPress through version 1.0.53. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing sensitive functions. An unauthenticated remote attacker can exploit this vulnerability by sending crafted network requests to the affected site. Successful exploitation allows the attacker to bypass intended security restrictions, potentially leading to unauthorized data access or modification of plugin settings. The issue is resolved in version 1.0.54.

Affected products

  • Arraytics Timetics n/a through 1.0.53

Timeline

  • 2026-01-13: other: Reported by Simone Maion
  • 2026-04-07: advisory: Patchstack advisory published
  • 2026-05-12: disclosed: CVE published to NVD

References

Related threats