sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total8
Critical4
High1
Medium3
Reset
Showing 1-8 of 8 records
Threat Entry Updated 2026-08-21

Truebooker Appointment Booking - Broken Access Control (CVE-2026-18315)

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including, 1.2.6. This is due to the admin_user_create_cus AJAX handler lacking any authentication or capability check before passing the attacker-supplied truebooker_wp_user_id parameter directly to wp_update_user. This makes it possible for unauthenticated attackers to overwrite the email address of any WordPress user — including an administrator — and then complete the standard WordPress lost-password flow to fully take over the targeted account.

PLUGIN Truebooker Appointment Booking

CVE-2026-18315

CRITICAL CVSS 9.8 2026-08-19
Threat Entry Updated 2026-08-20

Truebooker Appointment Booking - Security Vulnerability (CVE-2026-16142)

The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_update() AJAX handler being registered for unauthenticated users and accepting an arbitrary truebooker_wp_user_id value, which is passed directly to wp_update_user() without verifying authentication or ownership. This makes it possible for unauthenticated attackers to change any WordPress user account email address, including an administrator, by submitting the target user ID and an attacker-controlled email address. An attacker can then use the native WordPress password reset flow to receive…

PLUGIN Truebooker Appointment Booking

CVE-2026-16142

CRITICAL CVSS 9.8 2026-08-15
Threat Entry Updated 2026-08-12

Truebooker Appointment Booking - Broken Access Control (CVE-2026-14365)

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to change the password of arbitrary user accounts, including administrators, which can be leveraged to gain access to those accounts.

PLUGIN Truebooker Appointment Booking

CVE-2026-14365

CRITICAL CVSS 9.8 2026-08-07
Threat Entry Updated 2026-08-12

Truebooker Appointment Booking - Security Vulnerability (CVE-2026-14364)

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before resetting their password. This makes it possible for unauthenticated attackers to reset the password of arbitrary user accounts, including administrators, and gain access to those accounts.

PLUGIN Truebooker Appointment Booking

CVE-2026-14364

CRITICAL CVSS 9.8 2026-08-07
Threat Entry Updated 2026-07-28

Truebooker Appointment Booking - SQL Injection (CVE-2026-13161)

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The check_ajax_referer() nonce guard does not constitute an authentication or authorization barrier because the nonce…

PLUGIN Truebooker Appointment Booking

CVE-2026-13161

HIGH CVSS 7.5 2026-07-28
Threat Entry Updated 2026-06-17

Truebooker Appointment Booking - Information Disclosure (CVE-2026-1797)

The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 through views php files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed views php files via direct access.

PLUGIN Truebooker Appointment Booking

CVE-2026-1797

MEDIUM CVSS 5.3 2026-03-31