Impact
The TrueBooker WordPress plugin lacks proper authorization checks on several AJAX actions, enabling unauthenticated users to obtain customers’ personal data such as name, email, phone number, and postal address. This vulnerability is a classic example of CWE‑200, exposing confidential information without user consent.
Affected Systems
WordPress sites running any TrueBooker plugin version earlier than 1.2.7. The plugin is listed as "Unknown:TrueBooker" in CNA records, and the issue affects all installations that have not applied the patch available in version 1.2.7.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not cataloged in CISA’s KEV. Exploitation requires only sending unauthenticated HTTP requests to specific AJAX endpoints, meaning an attacker does not need any credentials or special privileges. The potential impact is moderate, consisting of a privacy breach and possible compliance violations if personal data is protected under regulations.
OpenCVE Enrichment