TrueBooker – Appointment Booking and Scheduler System <= 1.2.3 - Unauthenticated Privilege Escalation
2026-07-17 00:00
yangsoriStrategic Overview
StatusPatched in 1.2.4
Affected PluginTrueBooker – Appointment Booking and Scheduler System
Affected Version
<= 1.2.3CVSS9.8Critical
CVE
CVE-2026-61951Vulnerability Overview
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3. This makes it possible for unauthenticated attackers to elevate their privileges.
Technical Analysis
REMEDIATION: Update to version 1.2.4, or a newer patched version --- IDENTIFIER: CWE-266 (Incorrect Privilege Assignment) A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C