Description
Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
Published: 2026-07-23
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The TrueBooker plugin for WordPress with versions 1.2.3 and earlier contains an unauthenticated SQL injection flaw. The vulnerability allows an attacker to craft SQL statements that are executed directly against the WordPress database, enabling the attacker to read sensitive data, modify records, or potentially alter site configuration or content. This can lead to a full database compromise if exploited successfully.

Affected Systems

WordPress deployments that use the themetechmount TrueBooker plugin and are running version 1.2.3 or older are affected. Sites with the plugin updated to 1.2.4 or later are not impacted. If other providers or custom versions are in use, their risk status should be verified independently.

Risk and Exploitability

The CVSS score of 9.3 indicates a high severity level. The EPSS score of less than 1% suggests a low overall exploitation probability, yet the flaw is unauthenticated and can be triggered from the network, meaning any visitor could potentially exploit it. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can exploit the flaw by sending specially crafted requests to the plugin’s input endpoints without needing any authentication or privileged access.

Generated by OpenCVE AI on August 4, 2026 at 15:26 UTC.

Remediation

Vendor Solution

Update the WordPress TrueBooker Plugin to the latest available version (at least 1.2.4).


OpenCVE Recommended Actions

  • Update the TrueBooker plugin to version 1.2.4 or later.
  • If an update cannot be applied immediately, disable or remove the TrueBooker plugin to block the vulnerable functionality.
  • Configure firewall rules or request filtering to restrict external access to the plugin’s endpoints until the patch is in place.

Generated by OpenCVE AI on August 4, 2026 at 15:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Themetechmount
Themetechmount truebooker
Wordpress
Wordpress wordpress
Vendors & Products Themetechmount
Themetechmount truebooker
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
Title WordPress TrueBooker plugin <= 1.2.3 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Themetechmount Truebooker
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T14:52:23.970Z

Reserved: 2026-07-13T06:13:34.178Z

Link: CVE-2026-61950

cve-icon Vulnrichment

Updated: 2026-07-23T14:10:32.574Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:34.803

Modified: 2026-07-23T15:17:40.910

Link: CVE-2026-61950

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:30:06Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')