PatchSiren

TrueBooker CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM TrueBooker CVE published 2026-08-19

CVE-2026-18779

The TrueBooker WordPress plugin before 1.2.7 lacks proper authorisation checks in one of its AJAX actions. This allows unauthenticated users to delete arbitrary appointment records, along with associated booking items and payment records. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. To address this vulnerability, administrators and users of the TrueBooker WordPress plugi [truncated]