PatchSiren cyber security CVE debrief
CVE-2026-39663 themetechmount CVE debrief
A Missing Authorization vulnerability was found in the TrueBooker truebooker-appointment-booking plugin. This issue affects TrueBooker from n/a through version 1.1.5. The vulnerability allows Exploiting Incorrectly Configured Access Control Security Levels, with a CVSS score of 5.3 and a severity of MEDIUM. The CVE record was published on 2026-04-08T09:16:37.490Z and last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred. Users of the TrueBooker truebooker-appointment-booking plugin should be aware of this vulnerability and take necessary actions to mitigate the risk.
- Vendor
- themetechmount
- Product
- TrueBooker
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of the TrueBooker truebooker-appointment-booking plugin, security teams, and operators should be aware of this vulnerability and take necessary actions to mitigate the risk. Affected deployments should be identified and owners assigned for follow-up.
Technical summary
The CVE-2026-39663 vulnerability is caused by a Missing Authorization issue in the TrueBooker truebooker-appointment-booking plugin. This allows attackers to exploit incorrectly configured access control security levels. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. It affects TrueBooker from n/a through version 1.1.5.
Defensive priority
MEDIUM
Recommended defensive actions
- Inventory and verify the version of TrueBooker truebooker-appointment-booking plugin in use
- Apply the latest patch or update to version 1.1.6 or later if available
- Monitor for suspicious activity related to the plugin
- Consider implementing compensating controls to restrict access to the plugin
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
Evidence notes
The CVE record was published on 2026-04-08T09:16:37.490Z and last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred. The vulnerability affects TrueBooker from n/a through version 1.1.5, allowing Exploiting Incorrectly Configured Access Control Security Levels. Users should verify the version of TrueBooker truebooker-appointment-booking plugin in use and monitor for suspicious activity.
Official resources
-
CVE-2026-39663 CVE record
CVE.org
-
CVE-2026-39663 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:37.490Z and has not been modified since then. The NVD entry is currently Deferred.