Description
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
Published: 2026-07-23
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated privilege escalation flaw in WordPress TrueBooker plugin versions 1.2.3 and earlier, allowing an attacker to gain higher privileges that can lead to full control of the site or unauthorized access to sensitive data. The weakness falls under CWE‑266, which concerns inadequate authorization checks and is rated with a CVSS base score of 9.8, indicating a critical severity.

Affected Systems

The issue affects the TrueBooker appointment booking plugin for WordPress, distributed by themetechmount under the plugin slug TrueBooker. Versions 1.2.3 and all earlier releases are vulnerable; a fix is available in version 1.2.4.

Risk and Exploitability

The EPSS score of less than 1% suggests a currently low likelihood of exploitation, but the vulnerability remains highly dangerous because it provides unauthenticated users the ability to elevate privileges. It is not listed in the CISA KEV catalog. The attack vector is inferred to be web‑based, as the flaw allows the attacker to trigger privilege escalation via plugin endpoints without authentication.

Generated by OpenCVE AI on August 3, 2026 at 22:14 UTC.

Remediation

Vendor Solution

Update the WordPress TrueBooker Plugin to the latest available version (at least 1.2.4).


OpenCVE Recommended Actions

  • Upgrade the TrueBooker plugin to version 1.2.4 or newer.
  • If an immediate upgrade is not feasible, temporarily disable or uninstall the plugin until the patch can be applied.
  • Restrict the plugin's functionality to users with the Administrator role and block unauthenticated access to its endpoints by configuring WordPress capabilities or using a security plugin that limits plugin access.

Generated by OpenCVE AI on August 3, 2026 at 22:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Themetechmount
Themetechmount truebooker
Wordpress
Wordpress wordpress
Vendors & Products Themetechmount
Themetechmount truebooker
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
Title WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Themetechmount Truebooker
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T13:30:42.286Z

Reserved: 2026-07-13T06:13:34.178Z

Link: CVE-2026-61951

cve-icon Vulnrichment

Updated: 2026-07-23T13:30:37.366Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:34.923

Modified: 2026-07-23T14:17:32.853

Link: CVE-2026-61951

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:15:04Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment