PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18779 TrueBooker CVE debrief

The TrueBooker WordPress plugin before 1.2.7 lacks proper authorisation checks in one of its AJAX actions. This allows unauthenticated users to delete arbitrary appointment records, along with associated booking items and payment records. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. To address this vulnerability, administrators and users of the TrueBooker WordPress plugin, as well as security teams monitoring for potential data loss and unauthorised access, should review and restrict AJAX actions to authorised users. They should also verify the plugin version and update to 1.2.7 or later. Additionally, they should monitor for suspicious appointment record deletions and review compensating controls for exposed systems while remediation is scheduled and verified. Security teams should also check relevant monitoring, detection, and logs for exposed assets that need extra review. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and planning vendor-supported updates or mitigations through normal change control where exposure is confirmed. Affected operators and platforms should be assessed for potential impact, and vulnerability management and security teams should be informed to ensure proper mitigation and remediation efforts are in place. This may involve confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up. Overall, a coordinated effort is necessary to address the vulnerability effectively and minimize potential risks. The affected product or component is the TrueBooker WordPress plugin, and the vulnerability class is related to improper authorisation checks in AJAX actions. The likely operational impact is data loss and unauthorised access, and the source-confidence limits are based on evidence from WPScan and official CVE and NVD records. The review context includes verifying the plugin version, reviewing and restricting AJAX actions, and monitoring for suspicious activity. The defensive priority is medium due to the potential for data loss, and the recommended actions include verifying

Vendor
TrueBooker
Product
TrueBooker WordPress plugin
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-26
Advisory published
2026-08-19
Advisory updated
2026-08-26

Who should care

Administrators and users of the TrueBooker WordPress plugin, as well as security teams monitoring for potential data loss and unauthorised access, should review and restrict AJAX actions to authorised users. They should also verify the plugin version and update to 1.2.7 or later. Additionally, they should monitor for suspicious appointment record deletions and review compensating controls for exposed systems while remediation is scheduled and verified. Security teams should also check relevant monitoring, detection, and logs for exposed assets that need extra review. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and planning vendor-supported updates or mitigations through normal change control where exposure is confirmed. Affected operators and platforms should be assessed for potential impact, and vulnerability management and security teams should be informed to ensure proper mitigation and remediation efforts are in place. This may involve confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up. Overall, a coordinated effort is necessary to address the vulnerability effectively and minimize potential risks. The affected product or component is the TrueBooker WordPress plugin, and the vulnerability class is related to improper authorisation checks in AJAX actions. The likely operational impact is data loss and unauthorised access, and the source-confidence limits are based on evidence from WPScan and official CVE and NVD records. The review context includes verifying the plugin version, reviewing and restricting AJAX actions, and monitoring for suspicious activity. The defensive priority is medium due to the potential for data loss, and the recommended actions include verifying the plugin version, reviewing and restricting AJAX actions, and monitoring for suspicious activity. The affected operator impact includes administrators and users of the TrueBooker WordPress plugin, and the platform impact includes WordPress deployments with the TrueBooker plugin installed. The vulnerability management impact includes reviewing and

Technical summary

The TrueBooker WordPress plugin before 1.2.7 lacks proper authorisation checks in one of its AJAX actions. This allows unauthenticated users to delete arbitrary appointment records, along with associated booking items and payment records. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity.

Defensive priority

Medium priority due to potential for data loss

Recommended defensive actions

  • Verify TrueBooker plugin version and update to 1.2.7 or later
  • Review and restrict AJAX actions to authorised users
  • Monitor for suspicious appointment record deletions

Evidence notes

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records. Evidence from WPScan indicates a vulnerability in the TrueBooker WordPress plugin. Official CVE and NVD records provide additional context. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. To verify, defenders should review the plugin version, check for suspicious activity, and monitor for potential data loss.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-18779 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-18779

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-18779 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18779

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.