SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-18778

MEDIUM · CVSS 5.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The TrueBooker WordPress plugin prior to version 1.2.7 is vulnerable due to inadequate authorization checks in certain AJAX actions, enabling unauthenticated users to access sensitive customer information, such as names, email addresses, phone numbers, and postal addresses. This poses a significant privacy risk, making it crucial for WordPress site administrators using this plugin to prioritize updates to mitigate potential data breaches. Organizations handling customer data should urgently address this vulnerability to protect user privacy and comply with data protection regulations.

CVE
CVE-2026-18778
Severity
MEDIUM
CVSS
5.3
EPSS
0.25%
WordPress

Original NVD Description

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal information of customers who booked an appointment, including their name, email address, phone number and postal address.