Impact
The vulnerability is an unauthenticated privilege escalation flaw in WordPress TrueBooker plugin versions 1.2.3 and earlier, allowing an attacker to gain higher privileges that can lead to full control of the site or unauthorized access to sensitive data. The weakness falls under CWE‑266, which concerns inadequate authorization checks and is rated with a CVSS base score of 9.8, indicating a critical severity.
Affected Systems
The issue affects the TrueBooker appointment booking plugin for WordPress, distributed by themetechmount under the plugin slug TrueBooker. Versions 1.2.3 and all earlier releases are vulnerable; a fix is available in version 1.2.4.
Risk and Exploitability
The EPSS score of less than 1% suggests a currently low likelihood of exploitation, but the vulnerability remains highly dangerous because it provides unauthenticated users the ability to elevate privileges. It is not listed in the CISA KEV catalog. The attack vector is inferred to be web‑based, as the flaw allows the attacker to trigger privilege escalation via plugin endpoints without authentication.
OpenCVE Enrichment