CVE-2026-18778

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal information of customers who booked an appointment, including their name, email address, phone number and postal address.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-19 06:17

Updated : 2026-08-26 16:30


NVD link : CVE-2026-18778

Mitre link : CVE-2026-18778

CVE.ORG link : CVE-2026-18778


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor