Junglewise Threat Intelligence

CVE-2026-48881: TrueBooker Appointment Booking broken access control

CVE-2026-48881 · Severity: critical · CVSS 9.1 · Published 2026-06-15

Executive brief

TrueBooker is a WordPress plugin used for managing appointment bookings. A security flaw allows unauthorized individuals to bypass security checks and perform actions that should be restricted to administrators. This could lead to the theft of sensitive customer data or unauthorized changes to the website's booking system.

Technical details

The TrueBooker plugin for WordPress (versions 1.1.9 and below) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw by sending crafted requests to vulnerable functions that fail to validate user permissions or nonces. Successful exploitation allows the attacker to execute high-privileged actions, potentially leading to full data compromise or unauthorized modification of site settings. The issue is resolved in version 1.2.0.

Affected products

  • TrueBooker TrueBooker Appointment Booking <= 1.1.9

Timeline

  • 2026-05-18: other: Reported by researcher Vincent Sevkli
  • 2026-06-02: patched: Version 1.2.0 released and advisory published by Patchstack
  • 2026-06-15: advisory: CVE published in NVD

References