CVE-2026-18779

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-19 06:17

Updated : 2026-08-26 16:30


NVD link : CVE-2026-18779

Mitre link : CVE-2026-18779

CVE.ORG link : CVE-2026-18779


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization