Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical2
High1
Medium0
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2026-08-07

CVE-2026-14365 - TrueBooker – Appointment Booking and Scheduler System Theme

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to change the password of arbitrary user accounts, including administrators, which can be leveraged to gain access to those accounts.

THEME TrueBooker – Appointment Booking and Scheduler System

CVE-2026-14365

CRITICAL CVSS 9.8 2026-08-07
Threat Entry Updated 2026-08-07

CVE-2026-14364 - TrueBooker – Appointment Booking and Scheduler System Theme

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before resetting their password. This makes it possible for unauthenticated attackers to reset the password of arbitrary user accounts, including administrators, and gain access to those accounts.

THEME TrueBooker – Appointment Booking and Scheduler System

CVE-2026-14364

CRITICAL CVSS 9.8 2026-08-07
Threat Entry Updated 2026-07-28

CVE-2026-13161 - TrueBooker – Appointment Booking and Scheduler System Theme

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The check_ajax_referer() nonce guard does not constitute an authentication or authorization barrier because the nonce…

THEME TrueBooker – Appointment Booking and Scheduler System

CVE-2026-13161

HIGH CVSS 7.5 2026-07-28
Scroll to top