Description
Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions.
Published: 2026-10-06
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Settings Change
Action: Immediate Update
AI Analysis

Impact

WordPress sites running TrueBooker plugin version 1.2.9 or earlier are exposed to an unauthenticated settings change flaw that allows an attacker to modify plugin configuration without providing valid credentials. The vulnerability is a missing authorization issue, classified as CWE‑862, and can lead to unauthorized alterations of appointment booking parameters, potentially disabling services, redirecting booking information, or manipulating scheduling logic. The impact is a data integrity and availability problem that can affect end‑user scheduling and administrative accountability.

Affected Systems

The metastechMount TrueBooker plugin, available as part of WordPress installations, is vulnerable when its version is 1.2.9 or older. Any site using these plugin releases inherits the flaw, regardless of the underlying WordPress core version. No other plugin versions are listed as affected in the current advisory.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, and the EEPS value is not disclosed, which limits precise assessment of exploit likelihood. The advisory notes that the flaw is listed as not part of the CISA Known Exploited Vulnerabilities catalog. Attackers can exploit the weakness remotely over the web interface, requiring no authentication, making the attack path straightforward. Organizations should consider the moderate risk in their threat model and implement mitigation promptly.

Generated by OpenCVE AI on October 6, 2026 at 11:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the TrueBooker plugin to the latest version that addresses the settings‑change flaw.
  • Restrict plugin configuration permissions so that only trusted administrators can modify settings, reducing the potential impact of any access exploitation.
  • Verify the integrity of the site configuration and review logs for unauthorized changes following an update.

Generated by OpenCVE AI on October 6, 2026 at 11:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions.
Title WordPress TrueBooker plugin <= 1.2.9 - Settings Change vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-06T10:31:32.929Z

Reserved: 2026-04-07T10:59:21.050Z

Link: CVE-2026-39798

cve-icon Vulnrichment

Updated: 2026-10-06T10:29:16.270Z

cve-icon NVD

Status : Received

Published: 2026-10-06T09:17:52.990

Modified: 2026-10-06T11:17:26.870

Link: CVE-2026-39798

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T11:15:18Z

Weaknesses