Executive brief
TrueBooker is a WordPress plugin used by businesses to manage appointment bookings and scheduling. A security flaw in the plugin allows unauthorized individuals to bypass access controls due to missing authorization checks. This could allow an attacker to perform actions or modify settings that should be restricted to administrators, potentially disrupting booking operations.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the TrueBooker (truebooker-appointment-booking) plugin for WordPress. The issue stems from incorrectly configured access control security levels and a lack of proper authorization or nonce checks in certain functions. An unauthenticated remote attacker can exploit this to execute actions that should require higher privileges. The vulnerability affects versions up to and including 1.1.6 and is resolved in version 1.1.7.
Affected products
- themetechmount TrueBooker - Appointment Booking and Scheduler System <= 1.1.6
Timeline
- 2026-01-19: other: Vulnerability reported by Nabil Irawan
- 2026-02-18: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published to NVD