What the vulnerability does
01Description
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to change the password of arbitrary user accounts, including administrators, which can be leveraged to gain access to those accounts.
Explanation of Vulnerability in Simple Terms
02Summary
TrueBooker versions 1.2.3 and earlier lack authorization checks on core functionality. An unauthenticated attacker can read, modify, or delete appointment data and system settings without any credentials. This affects all installations and requires only network access to exploit.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete all appointment bookings and system configuration without logging in.
Potential impact on your site
04Site Impact
Complete compromise of appointment data and system integrity; attackers can cancel bookings, steal customer information, or disable the booking system.
Conditions required to exploit
05Prerequisites
Network access to the TrueBooker installation; no authentication or user interaction required.
Key dates
06Disclosure timeline
August 7, 2026
CVE published
August 7, 2026
Record updated