Executive brief
Arraytics Booktics, a WordPress plugin used for booking and scheduling, contains a security flaw where it fails to properly check user permissions. This could allow an unauthorized person to access information or perform actions that should be restricted to administrators. Organizations using this plugin should update to the latest version to prevent unauthorized access to their booking system.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Arraytics Booktics plugin for WordPress up to version 1.0.16. The flaw stems from incorrectly configured access control security levels, which fail to validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this to bypass intended access restrictions and potentially view sensitive data or modify settings. The issue is resolved in version 1.0.17.
Affected products
- Arraytics Booktics n/a through 1.0.16
Timeline
- 2026-01-03: disclosed: Reported by Simone Maion to Patchstack
- 2026-02-02: advisory: Patchstack published the vulnerability details
- 2026-04-08: advisory: NVD published the CVE record
- 2026-06-17: patched: Patchstack confirmed version 1.0.17 as the patched version