CyberRota Analysis
AI-GeneratedThe TrueBooker WordPress plugin prior to version 1.2.7 lacks adequate authorization checks in its AJAX actions, enabling unauthenticated users to delete arbitrary appointment records, including associated booking items and payment records. This vulnerability poses a significant risk to the integrity of appointment management for websites using this plugin. WordPress site administrators utilizing the TrueBooker plugin should prioritize immediate updates to mitigate potential unauthorized data loss.
Original NVD Description
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records.