Junglewise Threat Intelligence

CVE-2026-57674: Arraytics Timetics unauthenticated XSS

CVE-2026-57674 · Severity: high · CVSS 7.1 · Published 2026-07-02

Technologies: Arraytics Timetics. Vendors: Arraytics.

Executive brief

Timetics is a WordPress plugin used for appointment booking and scheduling. A security flaw allows an unauthenticated attacker to inject malicious scripts into the website, which could lead to unauthorized redirects, theft of user session data, or the display of fraudulent content to visitors. This occurs when a site administrator or visitor interacts with a specially crafted link or page created by the attacker.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Timetics WordPress plugin due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Successful exploitation requires a victim (typically a privileged user) to perform an action, such as clicking a malicious link. This can lead to session hijacking, unauthorized administrative actions, or website defacement. The issue is addressed in version 1.0.59.

Affected products

  • Arraytics Timetics <= 1.0.58

Timeline

  • 2026-06-20: other: Vulnerability reported by researcher daroo
  • 2026-06-30: patched: Patch released in version 1.0.59
  • 2026-07-02: disclosed: Public advisory published by Patchstack and NVD

References

Related threats