WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Timetics – Appointment Booking Calendar & Scheduling

Appointment booking and scheduling plugin with online booking calendar, payments, reminders, and calendar sync.

12Reported vulnerabilities
9.8Highest CVSS score
1.0.61Latest version
2,000+Active installs

What to do now

Update Timetics – Appointment Booking Calendar & Scheduling to 1.0.57 or later. 12 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 24, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-9263 Critical 9.8 1.1% 0 to 1.0.25 (inclusive)
0 to 1.0.25 (inclusive)
1.0.26 October 17, 2024
CVE-2024-1094 High 7.3 0.5% 0 to 1.0.21 (inclusive)
0 to 1.0.21 (inclusive)
1.0.22 June 14, 2024
CVE-2026-57674 High 7.2 0.3% 1.0.58 and earlier 1.0.59 June 30, 2026
CVE-2025-5919 Medium 6.5 0.2% 0 to 1.0.36 (inclusive) 1.0.37 January 6, 2026
CVE-2024-43923 Medium 5.3 0.5% 1.0.23 and earlier 1.0.24 August 26, 2024
CVE-2026-14322 Medium 5.3 0.3% 1.0.56 and earlier 1.0.57 July 1, 2026
CVE-2026-39432 Medium 5.3 0.2% 1.0.53 and earlier 1.0.54 April 7, 2026
CVE-2025-15473 Medium 5.3 0.2% Before 1.0.52 1.0.52 March 12, 2026
CVE-2025-67915 Medium 5.3 0.4% 1.0.46 and earlier 1.0.48 January 5, 2026
CVE-2025-64268 Medium 5.3 0.3% 1.0.44 and earlier 1.0.45 November 22, 2025
CVE-2025-30828 Medium 5.3 0.4% 1.0.29 and earlier 1.0.30 March 27, 2025
CVE-2024-11275 Medium 4.3 0.3% 0 to 1.0.27 (inclusive) 1.0.28 December 13, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.