WordPress security by component
TrueBooker
Plugin description
TrueBooker is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
truebooker-appointment-bookingLatest vulnerability
CVE-2026-61951: TrueBooker: Privilege escalation or authentication bypass
TrueBooker is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 1.2.3.
| Safe version |
|
||
|---|---|---|---|
| Jul 23, 2026 |
CVE-2026-61951
TrueBooker: Privilege escalation or authentication bypass
TrueBooker is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 1.2.3.
|
1.2.4 |
CVE9.8
NVDPending
|
| Jul 23, 2026 |
CVE-2026-61950
TrueBooker: SQL injection
TrueBooker is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.2.3.
|
1.2.4 |
CVE9.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-48881
TrueBooker: A security weakness
TrueBooker is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.1.9.
|
1.2.0 |
CVE9.1
NVDPending
|
| Apr 08, 2026 |
CVE-2026-39663
TrueBooker: A security weakness
TrueBooker is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.1.5.
|
> 1.1.5 |
CVE5.3
NVDPending
|
| Mar 31, 2026 |
CVE-2026-1797
TrueBooker – Appointment Booking and Scheduler System: Sensitive information exposure
TrueBooker – Appointment Booking and Scheduler System is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is <= 1.1.4.
|
> 1.1.4 |
CVE5.3
NVDPending
|
| Dec 09, 2025 |
CVE-2025-67581
TrueBooker: A security weakness
TrueBooker is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|