TrueBooker – Appointment Booking and Scheduler System < 1.2.7 - Unauthenticated Privilege Escalation
high
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 1.2.7. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for unauthenticated attackers to elevate their privileges beyo...
- CVSS:
- 7.3
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
- Disclosed:
- Aug 21, 2026
CVE-2026-18776 on NVD →
TrueBooker – Appointment Booking and Scheduler System < 1.2.7 - Missing Authorization
medium
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to unauthorized access in all versions up to 1.2.7. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
- Disclosed:
- Aug 21, 2026
CVE-2026-18779 on NVD →
TrueBooker – Appointment Booking and Scheduler System < 1.2.7 - Unauthenticated Information Exposure
medium
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 1.2.7. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
- Disclosed:
- Aug 21, 2026
CVE-2026-18778 on NVD →
TrueBooker – Appointment Booking and Scheduler System < 1.2.7 - Missing Authorization
medium
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to unauthorized access in all versions up to 1.2.7. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
- Disclosed:
- Aug 21, 2026
CVE-2026-18777 on NVD →
TrueBooker – Appointment Booking and Scheduler System <= 1.2.6 - Unauthenticated Privilege Escalation
high
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.6. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for unauthenticated attackers to elevate their...
- CVSS:
- 7.3
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.7
- Disclosed:
- Aug 19, 2026
CVE-2026-73347 on NVD →
TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter
critical
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including, 1.2.6. This is due to the admin_user_create_cus AJAX handler lacking any authentication or capability check b...
- CVSS:
- 9.8
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.7
- Disclosed:
- Aug 18, 2026
CVE-2026-18315 on NVD →
TrueBooker <= 1.2.6 - Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter
critical
The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_update() AJAX handler being registered for unauthenticated users and accepting an arbitrary truebooker_wp_user_id value, which is passed directly to wp_update_user() witho...
- CVSS:
- 9.8
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.7
- Disclosed:
- Aug 14, 2026
CVE-2026-16142 on NVD →
TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid'
critical
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before resetting their password. This makes it possible...
- CVSS:
- 9.8
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Aug 6, 2026
CVE-2026-14364 on NVD →
TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id'
critical
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to chang...
- CVSS:
- 9.8
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Aug 6, 2026
CVE-2026-14365 on NVD →
TrueBooker <= 1.2.2 - Unauthenticated SQL Injection
high
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQ...
- CVSS:
- 7.5
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.3
- Disclosed:
- Jul 27, 2026
CVE-2026-13161 on NVD →
TrueBooker – Appointment Booking and Scheduler System <= 1.2.3 - Unauthenticated Privilege Escalation
critical
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3. This makes it possible for unauthenticated attackers to elevate their privileges. CVE-2026-14545 is likely a duplicate of this.
- CVSS:
- 9.8
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Jul 17, 2026
CVE-2026-61951 on NVD →
TrueBooker – Appointment Booking and Scheduler System <= 1.2.3 - Unauthenticated SQL Injection
high
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...
- CVSS:
- 7.5
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Jul 16, 2026
CVE-2026-61950 on NVD →
TrueBooker – Appointment Booking and Scheduler System <= 1.1.9 - Missing Authorization
medium
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.1.9
- Fixed in:
- 1.2.0
- Disclosed:
- Jun 2, 2026
CVE-2026-48881 on NVD →
Truebooker - Appointment Booking and Scheduler Plugin <= 1.1.4 - Sensitive Information Exposure via Views Files
medium
The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 through views php files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed view...
- CVSS:
- 5.3
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.5
- Disclosed:
- Mar 30, 2026
CVE-2026-1797 on NVD →
TrueBooker <= 1.1.6 - Missing Authorization
medium
The TrueBooker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.1.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.7
- Disclosed:
- Feb 18, 2026
CVE-2026-39663 on NVD →
TrueBooker <= 1.1.0 - Missing Authorization
medium
The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.1
- Disclosed:
- Dec 15, 2025
CVE-2025-67581 on NVD →
TrueBooker <= 1.0.7 - Cross-Site Request Forgery
medium
The TrueBooker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.7. This is due to missing or incorrect nonce validation on several functions like truebooker_service_cat_remove_data(). This makes it possible for unauthenticated attackers to delete and modify data via...
- CVSS:
- 4.3
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.8
- Disclosed:
- May 7, 2025
CVE-2025-47543 on NVD →
TrueBooker <= 1.0.3 - Unauthenticated SQL Injection
critical
The TrueBooker – Appointment Booking and Scheduler Plugin. plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated...
- CVSS:
- 10
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.4
- Disclosed:
- Aug 10, 2024
CVE-2024-6924 on NVD →
TrueBooker <= 1.0.2 - Cross-Site Request Forgery to Settings Update
medium
The TrueBooker – Appointment Booking and Scheduler Plugin. plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to modify the plugin's setting...
- CVSS:
- 4.3
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.3
- Disclosed:
- Aug 10, 2024
CVE-2024-6925 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database