Description
Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Cross Site Request Forgery.This issue affects TrueBooker: from n/a through <= 1.0.7.
Published: 2025-05-07
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A cross‑site request forgery vulnerability in the TrueBooker WordPress plugin allows an attacker to cause authenticated site users to execute unintended actions without their knowledge. By tricking a logged‑in user into visiting a crafted URL, an attacker can trigger booking‑related state changes or other privileged operations, directly impacting the integrity and reliability of the booking system.

Affected Systems

The vulnerability applies to the TrueBooker plugin distributed by themetechmount for WordPress, affecting all versions up to and including 1.0.7. This plugin is typically integrated into WordPress sites that manage appointments and bookings.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk, and an EPSS score of less than 1% suggests that exploitation is unlikely but not impossible. The vulnerability is not currently listed in CISA KEV, implying it has not yet been observed in the wild. The likely attack vector involves a malicious link or image that a victim website administrator or regular user might click while authenticated, leading to credential‑leakage or accidental booking manipulation.

Generated by OpenCVE AI on April 30, 2026 at 20:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the TrueBooker plugin to a version newer than 1.0.7, eliminating the CSRF flaw.
  • If an upgrade is not immediately feasible, disable or uninstall the plugin to prevent any state‑changing operations until a patch is applied.
  • Add site‑wide CSRF protection such as nonce verification or referer checks to all vulnerable endpoints to mitigate potential exploitation of similar weaknesses.

Generated by OpenCVE AI on April 30, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-13793 Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker allows Cross Site Request Forgery. This issue affects TrueBooker: from n/a through 1.0.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker allows Cross Site Request Forgery. This issue affects TrueBooker: from n/a through 1.0.7. Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Cross Site Request Forgery.This issue affects TrueBooker: from n/a through <= 1.0.7.
Title WordPress TrueBooker <= 1.0.7 - Cross Site Request Forgery (CSRF) Vulnerability WordPress TrueBooker plugin <= 1.0.7 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00017}

epss

{'score': 0.0002}


Mon, 09 Jun 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Themetechmount
Themetechmount truebooker
CPEs cpe:2.3:a:themetechmount:truebooker:*:*:*:*:*:wordpress:*:*
Vendors & Products Themetechmount
Themetechmount truebooker

Wed, 07 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 May 2025 14:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker allows Cross Site Request Forgery. This issue affects TrueBooker: from n/a through 1.0.7.
Title WordPress TrueBooker <= 1.0.7 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Themetechmount Truebooker
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:44.430Z

Reserved: 2025-05-07T09:39:53.906Z

Link: CVE-2025-47543

cve-icon Vulnrichment

Updated: 2025-05-07T17:20:27.491Z

cve-icon NVD

Status : Modified

Published: 2025-05-07T15:16:10.977

Modified: 2026-04-23T15:30:27.250

Link: CVE-2025-47543

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T20:30:26Z

Weaknesses