CyberRota Analysis
AI-GeneratedThe TrueBooker WordPress plugin prior to version 1.2.7 is vulnerable due to inadequate authorization checks in its AJAX actions, enabling unauthenticated users to modify appointment statuses and send notification emails to customers. This flaw poses a risk of unauthorized access and manipulation of appointment data, potentially leading to customer confusion and trust issues. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger notification emails to the affected customers.