Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arraytics
Arraytics appointment Booking Calendar Wordpress Wordpress wordpress |
|
| Vendors & Products |
Arraytics
Arraytics appointment Booking Calendar Wordpress Wordpress wordpress |
Tue, 06 Jan 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the update and register_routes functions in all versions up to, and including, 1.0.36. This makes it possible for unauthenticated attackers to view and modify booking details. | |
| Title | Appointment Booking and Scheduling Calendar Plugin – WP Timetics <= 1.0.36 - Missing Authorization to Unauthenticated Booking Details View And Modification | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:26:57.217Z
Reserved: 2025-06-09T10:11:13.131Z
Link: CVE-2025-5919
Updated: 2026-01-06T14:27:42.066Z
Status : Deferred
Published: 2026-01-06T09:15:54.670
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-5919
No data.
OpenCVE Enrichment
Updated: 2026-04-20T19:00:10Z