« Volver al listado

Themetechmount

Themetechmount Truebooker: vulnerabilidades y CVE

Themetechmount Truebooker tiene 21 vulnerabilidades publicadas, 18 de ellas en los últimos 12 meses. 12 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE21
Últimos 12 meses18
Críticas12
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-14349Crítica (9.8)0.42%—16 sept 2026
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a…
CVE-2026-18315Crítica (9.8)0.60%—19 ago 2026
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including, 1.2.6.…
CVE-2026-73347Crítica (9.8)0.48%—19 ago 2026
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
CVE-2026-18779Media (5.3)0.30%—19 ago 2026
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated…
CVE-2026-18778Media (5.3)0.34%—19 ago 2026
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal information of customers who booked an…
CVE-2026-18777Media (5.3)0.30%—19 ago 2026
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger…
CVE-2026-18776Crítica (9.8)0.50%—19 ago 2026
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including…
CVE-2026-16142Crítica (9.8)0.66%—15 ago 2026
The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_update() AJAX handler being registered for unauthenticated users and…
CVE-2026-14365Crítica (9.8)0.56%—7 ago 2026
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a…
CVE-2026-14364Crítica (9.8)0.51%—7 ago 2026
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the…
CVE-2026-13161Alta (7.5)0.77%—28 jul 2026
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up to, and including, 1.2.2 due to…
CVE-2026-14545Crítica (9.8)0.50%—28 jul 2026
The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary…
CVE-2026-61951Crítica (9.8)0.48%—23 jul 2026
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
CVE-2026-61950Crítica (9.3)0.40%—23 jul 2026
Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
CVE-2026-48881Crítica (9.1)0.40%—15 jun 2026
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.
CVE-2026-39663Media (5.3)0.29%—8 abr 2026
Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TrueBooker: from n/a through <=…
CVE-2026-1797Media (5.3)0.21%—31 mar 2026
The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 through views php files. This makes it possible…
CVE-2025-67581Media (5.3)0.21%—9 dic 2025
Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TrueBooker: from n/a through <=…
CVE-2025-47543Media (4.3)0.17%—7 may 2025
Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Cross Site Request Forgery.This issue affects TrueBooker: from n/a through <= 1.0.7.
CVE-2024-6925Media (4.3)0.23%—8 sept 2024
The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
CVE-2024-6924Crítica (9.8)3.3%—8 sept 2024
The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application12
  2. T1098.002 Additional Email Delegate Permissions4
  3. T1078 Valid Accounts3
  4. T1005 Data from Local System2
  5. T1068 Exploitation for Privilege Escalation2
  6. T1098.001 Additional Cloud Credentials1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Themetechmount