CyberRota Analysis
AI-GeneratedThe TrueBooker WordPress plugin prior to version 1.2.7 is vulnerable due to inadequate authorization checks in certain AJAX actions, enabling unauthenticated users to access sensitive customer information, such as names, email addresses, phone numbers, and postal addresses. This poses a significant privacy risk, making it crucial for WordPress site administrators using this plugin to prioritize updates to mitigate potential data breaches. Organizations handling customer data should urgently address this vulnerability to protect user privacy and comply with data protection regulations.
Original NVD Description
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal information of customers who booked an appointment, including their name, email address, phone number and postal address.