Impact
The TrueBooker WordPress plugin version 1.2.6 and earlier lacks proper authorization checks on several AJAX actions. This flaw permits an unauthenticated visitor to modify the email address of any user, including administrators. Once the email is changed, the attacker can trigger a password reset email and gain control of that account. This is a classic Improper Access Control weakness (CWE-284) that results in full account takeover.
Affected Systems
This vulnerability applies to the TrueBooker appointment booking WordPress plugin with any version prior to 1.2.7. Sites running older releases are at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely but the vulnerability remains publicly known. It is not listed in CISA’s KEV catalog. The likely attack vector is via the website’s AJAX endpoints, which do not require authentication. An attacker could execute this exploitation without prior credentials, making it a low‑effort, high‑impact attack if the plugin is not updated.
OpenCVE Enrichment