WordPress Plugin Vulnerabilities

TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Account Takeover via Multiple AJAX Actions

Description

The plugin does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their account via the password reset flow.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Abdullah Kareem
Submitter
Abdullah Kareem
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-17 (about 3 days ago)
Added
2026-08-17 (about 2 days ago)
Last Updated
2026-08-19 (about 9 hours ago)

Other