What is CVE-2026-18779?
The TrueBooker WordPress plugin (versions below 1.2.7) lacks proper authorization checks in an AJAX action. This vulnerability allows unauthenticated attackers to delete arbitrary appointment, booking, and payment records. Users should immediately update to version 1.2.7 or later.
Azərbaycanca: TrueBooker WordPress plaginində (1.2.7 versiyasından əvvəl) avtorizasiya çatışmazlığı aşkar edilib. Bu zəiflik autentifikasiya olunmamış istifadəçilərə AJAX əməliyyatı vasitəsilə ixtiyari görüş, rezervasiya və ödəniş qeydlərini silməyə imkan verir. Plagini dərhal 1.2.7 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What can an unauthenticated attacker do in the TrueBooker plugin vulnerability?
An unauthenticated attacker can delete arbitrary appointment, booking, and payment records via an AJAX action.
To which version should the TrueBooker plugin be updated to fix CVE-2026-18779?
The plugin should be updated to version 1.2.7 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.