The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-19 06:17
Updated : 2026-08-26 16:30
NVD link : CVE-2026-18779
Mitre link : CVE-2026-18779
CVE.ORG link : CVE-2026-18779
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
