TrueBooker – Appointment Booking and Scheduler System
truebooker-appointment-booking · plugin
Known security vulnerabilities for TrueBooker – Appointment Booking and Scheduler System. Find out in seconds which version runs on your site with WP Lens.
14 known vulnerabilities
9 critical · 14 exploitable without logging in · 1 with public exploit code · latest Sep 16, 2026
Listed on wordpress.org · latest 1.2.9 · last updated Sep 18, 2026 · 600+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- Critical 9.8
CVE-2026-14349unauthenticated≤ 1.2.3
TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action
- Critical 9.8
CVE-2026-18315unauthenticated≤ 1.2.6
TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter
- Critical 9.8
CVE-2026-73347unauthenticated≤ 1.2.6
WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerability
- Critical 9.8
CVE-2026-16142unauthenticated≤ 1.2.6
TrueBooker <= 1.2.6 - Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter
- Critical 9.8
CVE-2026-14365unauthenticated≤ 1.2.3
TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id'
- Critical 9.8
CVE-2026-14364unauthenticated≤ 1.2.3
TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid'
- Critical 9.8
CVE-2026-61951unauthenticated≤ 1.2.3
WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability
- Critical 9.3
CVE-2026-61950unauthenticated≤ 1.2.3
WordPress TrueBooker plugin <= 1.2.3 - SQL Injection vulnerability
- Critical 9.1
CVE-2026-48881unauthenticated≤ 1.1.9
WordPress TrueBooker plugin <= 1.1.9 - Broken Access Control vulnerability
- High 7.5
CVE-2026-13161unauthenticated≤ 1.2.2
TrueBooker <= 1.2.2 - Unauthenticated SQL Injection
- Medium 5.3
CVE-2026-39663unauthenticated≤ 1.1.5
WordPress TrueBooker plugin <= 1.1.5 - Broken Access Control vulnerability
- Medium 5.3
CVE-2026-1797unauthenticated≤ 1.1.4
Truebooker - Appointment Booking and Scheduler Plugin <= 1.1.4 - Sensitive Information Exposure via Views Files
- Medium 5.3
CVE-2025-67581unauthenticated≤ 1.1.0
WordPress TrueBooker plugin <= 1.1.0 - Broken Access Control vulnerability
- Medium 4.3
CVE-2025-47543unauthenticated · needs a click≤ 1.0.7
WordPress TrueBooker plugin <= 1.0.7 - Cross Site Request Forgery (CSRF) Vulnerability
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).