Junglewise Threat Intelligence

CVE-2026-61951: Themetechmount TrueBooker privilege escalation

CVE-2026-61951 · Severity: critical · CVSS 9.8 · Published 2026-07-23

Executive brief

TrueBooker is a WordPress plugin used for managing appointments and scheduling. A critical security flaw allows unauthenticated attackers to gain administrative control over the website. This could lead to complete site takeover, data theft, or the installation of malicious software.

Technical details

The TrueBooker plugin for WordPress (versions 1.2.3 and below) is vulnerable to unauthenticated privilege escalation due to incorrect privilege assignment (CWE-266). An attacker can exploit this vulnerability over the network without any prior authentication or user interaction. Successful exploitation allows a remote actor to escalate their privileges to an administrative level, granting full control over the affected WordPress site. The issue is resolved in version 1.2.4.

Affected products

  • themetechmount TrueBooker - Appointment Booking and Scheduler System <= 1.2.3

Timeline

  • 2026-05-27: other: Reported by researcher yangsori
  • 2026-07-17: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: NVD publication date

References