// For flags

CVE-2024-9263

WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.25 - Insecure Direct Object Reference to Unauthenticated Arbitrary User Password/Email Reset/Account Takeover

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.0.25 via the save() due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to reset the emails and passwords of arbitrary user accounts, including administrators, which makes account takeover and privilege escalation possible.

El complemento WP Timetics - AI-powered Appointment Booking Calendar and Online Scheduling Plugin para WordPress es vulnerable a la apropiación de cuentas/escalada de privilegios a través de una referencia directa a objetos insegura en todas las versiones hasta la 1.0.25 incluida a través de save() debido a la falta de validación en una clave controlada por el usuario. Esto hace posible que atacantes no autenticados restablezcan los correos electrónicos y las contraseñas de cuentas de usuario arbitrarias, incluidos los administradores, lo que hace posible la apropiación de cuentas y la escalada de privilegios.

*Credits: wesley
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2024-09-26 CVE Reserved
  • 2024-10-16 CVE Published
  • 2024-10-17 CVE Updated
  • 2024-10-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Arraytics
Search vendor "Arraytics"
WP Timetics- AI-powered Appointment Booking Calendar And Online Scheduling Plugin
Search vendor "Arraytics" for product "WP Timetics- AI-powered Appointment Booking Calendar And Online Scheduling Plugin"
<= 1.0.25
Search vendor "Arraytics" for product "WP Timetics- AI-powered Appointment Booking Calendar And Online Scheduling Plugin" and version " <= 1.0.25"
en
Affected