Impact
The TrueBooker plugin for WordPress with versions 1.2.3 and earlier contains an unauthenticated SQL injection flaw. The vulnerability allows an attacker to craft SQL statements that are executed directly against the WordPress database, enabling the attacker to read sensitive data, modify records, or potentially alter site configuration or content. This can lead to a full database compromise if exploited successfully.
Affected Systems
WordPress deployments that use the themetechmount TrueBooker plugin and are running version 1.2.3 or older are affected. Sites with the plugin updated to 1.2.4 or later are not impacted. If other providers or custom versions are in use, their risk status should be verified independently.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity level. The EPSS score of less than 1% suggests a low overall exploitation probability, yet the flaw is unauthenticated and can be triggered from the network, meaning any visitor could potentially exploit it. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can exploit the flaw by sending specially crafted requests to the plugin’s input endpoints without needing any authentication or privileged access.
OpenCVE Enrichment