What is CVE-2026-18777?
CVE-2026-18777: The TrueBooker WordPress plugin before version 1.2.7 lacks proper authorization checks in one of its AJAX actions, allowing unauthenticated users to change arbitrary appointment statuses and trigger notification emails to customers. This vulnerability could be exploited to manipulate booking data. Affected sites should immediately update the plugin to the latest version.
Azərbaycanca: CVE-2026-18777: TrueBooker WordPress plaginində (1.2.7 versiyasından əvvəl) AJAX əməliyyatlarında autorizasiya yoxlanışının olmaması səbəbindən autentifikasiya olunmamış istifadəçilər ixtiyari randevuların statusunu dəyişə və müştərilərə bildiriş e-poçtları göndərə bilərlər. Bu zəiflikdən istifadə edərək hücumçular rezervasiya məlumatlarını manipulyasiya edə bilər. Təsirə məruz qalan saytlar dərhal plaqini ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which version of the TrueBooker plugin is affected by CVE-2026-18777?
All versions of the TrueBooker WordPress plugin before version 1.2.7 are affected by this vulnerability.
What can an unauthenticated attacker do by exploiting CVE-2026-18777?
An unauthenticated attacker can change arbitrary appointment statuses and trigger notification emails to customers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.