SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-18777

MEDIUM · CVSS 5.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The TrueBooker WordPress plugin prior to version 1.2.7 is vulnerable due to inadequate authorization checks in its AJAX actions, enabling unauthenticated users to modify appointment statuses and send notification emails to customers. This flaw poses a risk of unauthorized access and manipulation of appointment data, potentially leading to customer confusion and trust issues. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-18777
Severity
MEDIUM
CVSS
5.3
EPSS
0.22%
WordPress

Original NVD Description

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger notification emails to the affected customers.