VYPR

Truebooker

by WordPress

Source repositories

CVEs (18)

  • CVE-2026-73347CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.

  • CVE-2026-18776CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.00

    The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their account via the password…

  • CVE-2024-6924CriSep 8, 2024
    risk 0.64cvss 9.8epss 0.03

    The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

  • CVE-2026-48881CriJun 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.

  • CVE-2026-18315CriAug 19, 2026
    risk 0.57cvss 9.8epss 0.01

    The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including, 1.2.6. This is due to the admin_user_create_cus AJAX handler…

  • CVE-2026-16142CriAug 15, 2026
    risk 0.57cvss 9.8epss 0.00

    The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_update() AJAX handler being registered for unauthenticated users and accepting an arbitrary truebooker_wp_user_id value, which is…

  • CVE-2026-14365CriAug 7, 2026
    risk 0.57cvss 9.8epss 0.00

    The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-14364CriAug 7, 2026
    risk 0.57cvss 9.8epss 0.00

    The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before…

  • CVE-2026-18779MedAug 19, 2026
    risk 0.34cvss 5.3epss 0.00

    The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records.

  • CVE-2026-18778MedAug 19, 2026
    risk 0.34cvss 5.3epss 0.00

    The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal information of customers who booked an appointment, including their name, email address, phone number and…

  • CVE-2026-18777MedAug 19, 2026
    risk 0.34cvss 5.3epss 0.00

    The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger notification emails to the affected customers.

  • CVE-2026-39663MedApr 8, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TrueBooker: from n/a through <= 1.1.5.

  • CVE-2026-1797MedMar 31, 2026
    risk 0.34cvss 5.3epss 0.00

    The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 through views php files. This makes it possible for unauthenticated attackers to view potentially…

  • CVE-2025-67581MedDec 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TrueBooker: from n/a through <= 1.1.0.

  • CVE-2025-47543MedMay 7, 2025
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Cross Site Request Forgery.This issue affects TrueBooker: from n/a through <= 1.0.7.

  • CVE-2024-6925MedSep 8, 2024
    risk 0.28cvss 4.3epss 0.00

    The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

  • CVE-2026-14545CriJul 28, 2026
    risk 0.00cvss 9.8epss 0.00

    The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take…

  • CVE-2026-61950CriJul 23, 2026
    risk 0.00cvss 9.3epss 0.00

    Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.