plugin

Truebooker Appointment Booking Vulnerabilities

19 known security issues reported for the Truebooker Appointment Booking WordPress plugin. Most recent disclosed Aug 21, 2026.

6 critical 4 high 9 medium

Running Truebooker Appointment Booking on your site? Check whether your installed version is affected.

Scan your site free

TrueBooker – Appointment Booking and Scheduler System < 1.2.7 - Unauthenticated Privilege Escalation

high

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 1.2.7. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for unauthenticated attackers to elevate their privileges beyo...

CVSS:
7.3
Affected:
up to 1.2.7
Fixed in:
1.2.7
Disclosed:
Aug 21, 2026

CVE-2026-18776 on NVD →

TrueBooker – Appointment Booking and Scheduler System < 1.2.7 - Missing Authorization

medium

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to unauthorized access in all versions up to 1.2.7. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.2.7
Fixed in:
1.2.7
Disclosed:
Aug 21, 2026

CVE-2026-18779 on NVD →

TrueBooker – Appointment Booking and Scheduler System < 1.2.7 - Unauthenticated Information Exposure

medium

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 1.2.7. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 1.2.7
Fixed in:
1.2.7
Disclosed:
Aug 21, 2026

CVE-2026-18778 on NVD →

TrueBooker – Appointment Booking and Scheduler System < 1.2.7 - Missing Authorization

medium

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to unauthorized access in all versions up to 1.2.7. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.2.7
Fixed in:
1.2.7
Disclosed:
Aug 21, 2026

CVE-2026-18777 on NVD →

TrueBooker – Appointment Booking and Scheduler System <= 1.2.6 - Unauthenticated Privilege Escalation

high

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.6. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for unauthenticated attackers to elevate their...

CVSS:
7.3
Affected:
up to 1.2.6
Fixed in:
1.2.7
Disclosed:
Aug 19, 2026

CVE-2026-73347 on NVD →

TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter

critical

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including, 1.2.6. This is due to the admin_user_create_cus AJAX handler lacking any authentication or capability check b...

CVSS:
9.8
Affected:
up to 1.2.6
Fixed in:
1.2.7
Disclosed:
Aug 18, 2026

CVE-2026-18315 on NVD →

TrueBooker <= 1.2.6 - Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter

critical

The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_update() AJAX handler being registered for unauthenticated users and accepting an arbitrary truebooker_wp_user_id value, which is passed directly to wp_update_user() witho...

CVSS:
9.8
Affected:
up to 1.2.6
Fixed in:
1.2.7
Disclosed:
Aug 14, 2026

CVE-2026-16142 on NVD →

TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid'

critical

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before resetting their password. This makes it possible...

CVSS:
9.8
Affected:
up to 1.2.3
Fixed in:
1.2.4
Disclosed:
Aug 6, 2026

CVE-2026-14364 on NVD →

TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id'

critical

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to chang...

CVSS:
9.8
Affected:
up to 1.2.3
Fixed in:
1.2.4
Disclosed:
Aug 6, 2026

CVE-2026-14365 on NVD →

TrueBooker <= 1.2.2 - Unauthenticated SQL Injection

high

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQ...

CVSS:
7.5
Affected:
up to 1.2.2
Fixed in:
1.2.3
Disclosed:
Jul 27, 2026

CVE-2026-13161 on NVD →

TrueBooker – Appointment Booking and Scheduler System <= 1.2.3 - Unauthenticated Privilege Escalation

critical

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3. This makes it possible for unauthenticated attackers to elevate their privileges. CVE-2026-14545 is likely a duplicate of this.

CVSS:
9.8
Affected:
up to 1.2.3
Fixed in:
1.2.4
Disclosed:
Jul 17, 2026

CVE-2026-61951 on NVD →

TrueBooker – Appointment Booking and Scheduler System <= 1.2.3 - Unauthenticated SQL Injection

high

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...

CVSS:
7.5
Affected:
up to 1.2.3
Fixed in:
1.2.4
Disclosed:
Jul 16, 2026

CVE-2026-61950 on NVD →

TrueBooker – Appointment Booking and Scheduler System <= 1.1.9 - Missing Authorization

medium

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.1.9
Fixed in:
1.2.0
Disclosed:
Jun 2, 2026

CVE-2026-48881 on NVD →

Truebooker - Appointment Booking and Scheduler Plugin <= 1.1.4 - Sensitive Information Exposure via Views Files

medium

The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 through views php files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed view...

CVSS:
5.3
Affected:
up to 1.1.4
Fixed in:
1.1.5
Disclosed:
Mar 30, 2026

CVE-2026-1797 on NVD →

TrueBooker <= 1.1.6 - Missing Authorization

medium

The TrueBooker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.1.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.1.6
Fixed in:
1.1.7
Disclosed:
Feb 18, 2026

CVE-2026-39663 on NVD →

TrueBooker <= 1.1.0 - Missing Authorization

medium

The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.1.0
Fixed in:
1.1.1
Disclosed:
Dec 15, 2025

CVE-2025-67581 on NVD →

TrueBooker <= 1.0.7 - Cross-Site Request Forgery

medium

The TrueBooker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.7. This is due to missing or incorrect nonce validation on several functions like truebooker_service_cat_remove_data(). This makes it possible for unauthenticated attackers to delete and modify data via...

CVSS:
4.3
Affected:
up to 1.0.7
Fixed in:
1.0.8
Disclosed:
May 7, 2025

CVE-2025-47543 on NVD →

TrueBooker <= 1.0.3 - Unauthenticated SQL Injection

critical

The TrueBooker – Appointment Booking and Scheduler Plugin. plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated...

CVSS:
10
Affected:
up to 1.0.3
Fixed in:
1.0.4
Disclosed:
Aug 10, 2024

CVE-2024-6924 on NVD →

TrueBooker <= 1.0.2 - Cross-Site Request Forgery to Settings Update

medium

The TrueBooker – Appointment Booking and Scheduler Plugin. plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to modify the plugin's setting...

CVSS:
4.3
Affected:
up to 1.0.2
Fixed in:
1.0.3
Disclosed:
Aug 10, 2024

CVE-2024-6925 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database