Themetechmount
Themetechmount Truebooker: vulnerabilities and CVEs
Themetechmount Truebooker has 21 published vulnerabilities, 18 of them in the last 12 months. 12 are rated critical and 0 are listed by CISA as actively exploited.
CVEs21
Last 12 months18
Critical12
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14349 | Critical (9.8) | 0.42% | — | Sep 16, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a… |
| CVE-2026-18315 | Critical (9.8) | 0.60% | — | Aug 19, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including, 1.2.6.… |
| CVE-2026-73347 | Critical (9.8) | 0.48% | — | Aug 19, 2026 | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. |
| CVE-2026-18779 | Medium (5.3) | 0.30% | — | Aug 19, 2026 | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated… |
| CVE-2026-18778 | Medium (5.3) | 0.34% | — | Aug 19, 2026 | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal information of customers who booked an… |
| CVE-2026-18777 | Medium (5.3) | 0.30% | — | Aug 19, 2026 | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger… |
| CVE-2026-18776 | Critical (9.8) | 0.50% | — | Aug 19, 2026 | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including… |
| CVE-2026-16142 | Critical (9.8) | 0.66% | — | Aug 15, 2026 | The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_update() AJAX handler being registered for unauthenticated users and… |
| CVE-2026-14365 | Critical (9.8) | 0.56% | — | Aug 7, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a… |
| CVE-2026-14364 | Critical (9.8) | 0.51% | — | Aug 7, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the… |
| CVE-2026-13161 | High (7.5) | 0.77% | — | Jul 28, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up to, and including, 1.2.2 due to… |
| CVE-2026-14545 | Critical (9.8) | 0.50% | — | Jul 28, 2026 | The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary… |
| CVE-2026-61951 | Critical (9.8) | 0.48% | — | Jul 23, 2026 | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. |
| CVE-2026-61950 | Critical (9.3) | 0.40% | — | Jul 23, 2026 | Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. |
| CVE-2026-48881 | Critical (9.1) | 0.40% | — | Jun 15, 2026 | Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions. |
| CVE-2026-39663 | Medium (5.3) | 0.29% | — | Apr 8, 2026 | Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TrueBooker: from n/a through <=… |
| CVE-2026-1797 | Medium (5.3) | 0.21% | — | Mar 31, 2026 | The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 through views php files. This makes it possible… |
| CVE-2025-67581 | Medium (5.3) | 0.21% | — | Dec 9, 2025 | Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TrueBooker: from n/a through <=… |
| CVE-2025-47543 | Medium (4.3) | 0.16% | — | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Cross Site Request Forgery.This issue affects TrueBooker: from n/a through <= 1.0.7. |
| CVE-2024-6925 | Medium (4.3) | 0.23% | — | Sep 8, 2024 | The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. |
| CVE-2024-6924 | Critical (9.8) | 3.3% | — | Sep 8, 2024 | The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.