Impact
WordPress sites running TrueBooker plugin version 1.2.9 or earlier are exposed to an unauthenticated settings change flaw that allows an attacker to modify plugin configuration without providing valid credentials. The vulnerability is a missing authorization issue, classified as CWE‑862, and can lead to unauthorized alterations of appointment booking parameters, potentially disabling services, redirecting booking information, or manipulating scheduling logic. The impact is a data integrity and availability problem that can affect end‑user scheduling and administrative accountability.
Affected Systems
The metastechMount TrueBooker plugin, available as part of WordPress installations, is vulnerable when its version is 1.2.9 or older. Any site using these plugin releases inherits the flaw, regardless of the underlying WordPress core version. No other plugin versions are listed as affected in the current advisory.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EEPS value is not disclosed, which limits precise assessment of exploit likelihood. The advisory notes that the flaw is listed as not part of the CISA Known Exploited Vulnerabilities catalog. Attackers can exploit the weakness remotely over the web interface, requiring no authentication, making the attack path straightforward. Organizations should consider the moderate risk in their threat model and implement mitigation promptly.
OpenCVE Enrichment