Executive brief
Timetics is a WordPress plugin that allows users to manage time-related features on their websites. The plugin contains an unauthenticated broken access control vulnerability that allows unauthorized users to access pages and perform actions they should not be permitted to do, potentially exposing sensitive data or enabling unauthorized modifications to website content.
Technical details
The vulnerability is a broken access control issue (OWASP A1) affecting Timetics versions up to 1.0.61. It allows unauthenticated attackers to access restricted pages or perform privileged actions without requiring authentication or proper authorization checks. The vulnerability is remotely exploitable over the network with no authentication required. An attacker can access sensitive data or perform unauthorized actions through the affected plugin. The vulnerability was patched in version 1.0.62.
Affected products
- Arraytics Timetics <= 1.0.61
Timeline
- 2026-09-03: disclosed
- 2026-09-03: patched: Version 1.0.62 released