Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

TrueBooker — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in TrueBooker, with AI-generated Chinese analysis, references, and POCs.

This page provides vulnerability aggregation data for TrueBooker, focusing on common software weakness classifications such as buffer overflows and injection flaws. It compiles records of security issues identified across various versions of the TrueBooker booking and reservation system, covering publicly disclosed advisories from 2018 through 2024. By reviewing this collection, users can systematically track a vendor’s security response patterns and advisory release timelines. The data allows researchers to understand how specific weakness classes impact the TrueBooker architecture and its associated integrations. Additionally, it serves as a comprehensive lookup tool for anyone investigating the historical vulnerability profile of this specific product. This resource is designed to support security analysts, developers, and compliance officers in assessing risk exposure and understanding the evolution of security patches for TrueBooker deployments. The aggregated information highlights trends in defect discovery and remediation speeds, offering insight into the overall security posture of the software. Users interested in deeper technical details are encouraged to cross-reference these findings with official vendor bulletins and independent security research reports to verify the scope and severity of each reported issue. This structured overview aims to provide a clear, factual basis for decision-making regarding software updates and mitigation strategies without speculation or external commentary. The focus remains strictly on documented evidence and verified disclosures related to the product's known security deficiencies.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-73347 WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerability CWE-266 9.8 Critical 2026-08-19
CVE-2026-18776 TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Account Takeover via Multiple AJAX Actions - - 2026-08-19
CVE-2026-18778 TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Customer PII Disclosure via Multiple AJAX Actions - - 2026-08-19
CVE-2026-18777 TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointment Status Change via update_appointment_status - - 2026-08-19
CVE-2026-18779 TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appointment and Payment Record Deletion via update_appointment_booked - - 2026-08-19
CVE-2026-14545 TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password Reset - - 2026-07-28
CVE-2026-61951 WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability CWE-266 9.8 Critical 2026-07-23
CVE-2026-61950 WordPress TrueBooker plugin <= 1.2.3 - SQL Injection vulnerability CWE-89 9.3 Critical 2026-07-23
CVE-2026-48881 WordPress TrueBooker plugin <= 1.1.9 - Broken Access Control vulnerability CWE-862 9.1 Critical 2026-06-15
CVE-2026-39663 WordPress TrueBooker plugin <= 1.1.5 - Broken Access Control vulnerability CWE-862 5.3 Medium 2026-04-08
CVE-2025-67581 WordPress TrueBooker plugin <= 1.1.0 - Broken Access Control vulnerability CWE-862 5.3 Medium 2025-12-09
CVE-2025-47543 WordPress TrueBooker plugin <= 1.0.7 - Cross Site Request Forgery (CSRF) Vulnerability CWE-352 4.3 Medium 2025-05-07
CVE-2024-6924 TrueBooker < 1.0.3 - Multiple Unauthenticated SQLi 9.8AI Critical AI 2024-09-08
CVE-2024-6925 TrueBooker < 1.0.3 - Settings Update via CSRF 4.3AI Medium AI 2024-09-08

All 14 known CVE vulnerabilities affecting TrueBooker with full Chinese analysis, references, and POCs where available.