What is CVE-2026-14322?
CVE-2026-14322 is a vulnerability in the Timetics WordPress plugin (before 1.0.57) that fails to enforce a pending or unpaid status. This allows unauthenticated users to create fully-approved bookings for priced appointments without making any payment via methods other than recognized gateways.
Azərbaycanca: CVE-2026-14322 Timetics WordPress pluginində (1.0.57-dən əvvəl) ödəniş statusunun yoxlanılmaması zəifliyidir. Bu, autentifikasiya olunmamış istifadəçilərə tanınmış ödəniş şlüzlərindən kənar üsullarla ödəniş etmədən təsdiqlənmiş rezervasiya yaratmağa imkan verir.
FAQ2
Which versions of the Timetics plugin are affected by CVE-2026-14322?
This vulnerability affects versions of the Timetics WordPress plugin before 1.0.57.
What can an unauthenticated user do by exploiting CVE-2026-14322?
An unauthenticated user can create fully-approved bookings for priced appointments without making any payment.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.