Junglewise Threat Intelligence

CVE-2026-61950: themetechmount TrueBooker SQL injection

CVE-2026-61950 · Severity: critical · CVSS 9.3 · Published 2026-07-23

Executive brief

TrueBooker is a WordPress plugin used for managing appointment bookings. A critical security flaw allows unauthorized individuals to interact directly with the website's database without needing a password. This could lead to the theft of sensitive customer information, unauthorized access to administrative data, or disruption of the booking service.

Technical details

A SQL injection vulnerability exists in the TrueBooker plugin for WordPress (versions <= 1.2.3) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is exploitable by an unauthenticated attacker over the network with low complexity. By sending specially crafted requests, an attacker can bypass authentication to read, modify, or delete data within the underlying database. The vulnerability has been addressed in version 1.2.4.

Affected products

  • themetechmount TrueBooker - Appointment Booking System <= 1.2.3

Timeline

  • 2026-05-19: disclosed: Reported by HaiND to Patchstack
  • 2026-07-16: advisory: Patchstack published advisory
  • 2026-07-23: advisory: NVD published CVE record
  • 2026-07-23: patched: Version 1.2.4 confirmed as patched version

References