PT-2026-39947 · WordPress · Timetics

Published

2026-05-12

·

Updated

2026-05-12

·

CVE-2026-39432

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Timetics versions prior to 1.0.54
Description A missing authorization issue in the Timetics plugin allows for the exploitation of incorrectly configured access control security levels. This flaw permits unauthorized access control bypass, exposing administrative functions to unauthenticated actors.
Recommendations Update to the latest version.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-39432

Affected Products

Timetics