What is CVE-2026-18778?
CVE-2026-18778 is a vulnerability in the TrueBooker WordPress plugin before version 1.2.7. The lack of proper authorization checks in some AJAX actions allows unauthenticated users to retrieve personal information of appointment customers, including names, email addresses, phone numbers, and postal addresses. Users should update to the latest version immediately.
Azərbaycanca: CVE-2026-18778, TrueBooker WordPress plaginindəki zəiflikdir (1.2.7-dən əvvəlki versiyalar). Bu zəiflik bəzi AJAX əməliyyatlarında düzgün autorizasiya yoxlanışının olmaması səbəbindən autentifikasiya olunmamış istifadəçilərə müştərilərin ad, e-poçt, telefon və ünvan kimi şəxsi məlumatlarını əldə etməyə imkan verir. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the TrueBooker plugin are affected by CVE-2026-18778?
This vulnerability affects the TrueBooker WordPress plugin in versions before 1.2.7.
What kind of personal information can be exposed via CVE-2026-18778?
By exploiting this vulnerability, unauthenticated users can retrieve personal information of customers, including names, email addresses, phone numbers, and postal addresses.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.