MEDIUM
TrueBooker
CVE published 2026-08-19
CVE-2026-18779
The TrueBooker WordPress plugin before 1.2.7 lacks proper authorisation checks in one of its AJAX actions. This allows unauthenticated users to delete arbitrary appointment records, along with associated booking items and payment records. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. To address this vulnerability, administrators and users of the TrueBooker WordPress plugi [truncated]