CVE-2026-18777

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger notification emails to the affected customers.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-19 06:17

Updated : 2026-08-26 16:30


NVD link : CVE-2026-18777

Mitre link : CVE-2026-18777

CVE.ORG link : CVE-2026-18777


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization