Junglewise Threat Intelligence

CVE-2026-84215: Timetics broken access control

CVE-2026-84215 · Severity: medium · CVSS 6.5 · Published 2026-09-03

Technologies: Arraytics Timetics. Vendors: Arraytics.

Executive brief

Timetics is a WordPress plugin that allows users to manage time-related features on their websites. The plugin contains an unauthenticated broken access control vulnerability that allows unauthorized users to access pages and perform actions they should not be permitted to do, potentially exposing sensitive data or enabling unauthorized modifications to website content.

Technical details

The vulnerability is a broken access control issue (OWASP A1) affecting Timetics versions up to 1.0.61. It allows unauthenticated attackers to access restricted pages or perform privileged actions without requiring authentication or proper authorization checks. The vulnerability is remotely exploitable over the network with no authentication required. An attacker can access sensitive data or perform unauthorized actions through the affected plugin. The vulnerability was patched in version 1.0.62.

Affected products

  • Arraytics Timetics <= 1.0.61

Timeline

  • 2026-09-03: disclosed
  • 2026-09-03: patched: Version 1.0.62 released

References

Related threats