SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-18779

MEDIUM · CVSS 5.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The TrueBooker WordPress plugin prior to version 1.2.7 lacks adequate authorization checks in its AJAX actions, enabling unauthenticated users to delete arbitrary appointment records, including associated booking items and payment records. This vulnerability poses a significant risk to the integrity of appointment management for websites using this plugin. WordPress site administrators utilizing the TrueBooker plugin should prioritize immediate updates to mitigate potential unauthorized data loss.

CVE
CVE-2026-18779
Severity
MEDIUM
CVSS
5.3
EPSS
0.22%
WordPress

Original NVD Description

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records.