WordPress Plugin Vulnerabilities

TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appointment and Payment Record Deletion via update_appointment_booked

Description

The plugin does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records.

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Erwan LR (WPScan)
Submitter
Erwan LR (WPScan)
Verified
Yes

Timeline

Publicly Published
2026-08-17 (about 3 days ago)
Added
2026-08-17 (about 2 days ago)
Last Updated
2026-08-17 (about 2 days ago)

Other