What is CVE-2026-13161?
The TrueBooker WordPress plugin is vulnerable to SQL Injection via the `alldata[truebooker_user]` parameter. This affects versions up to and including 1.2.2. Immediate plugin update is required for remediation.
Azərbaycanca: TrueBooker WordPress pluginində `alldata[truebooker_user]` parametri vasitəsilə SQL Injection zəifliyi aşkar edilib. 1.2.2 və daha əvvəlki versiyaları təsir edir. Plugin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Through which parameter can the SQL Injection vulnerability in the TrueBooker WordPress plugin be exploited?
The vulnerability can be exploited via the `alldata[truebooker_user]` parameter.
Which versions of TrueBooker are affected by CVE-2026-13161?
Versions up to and including 1.2.2 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.