Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

themetechmount — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting themetechmount. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Themetechmount develops WordPress themes and plugins for website building, with a core use case of creating customizable templates for online businesses. Historically, their products have been vulnerable to remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from insufficient input validation and improper access controls. The organization has accumulated five CVEs, reflecting recurring security gaps in their codebase. While no major public incidents have been documented, their vulnerability pattern suggests a need for enhanced security testing and secure coding practices to mitigate risks for their user base.

CVE ID Title CVSS Severity Published
CVE-2026-18315 TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter — TrueBooker – Appointment Booking and Scheduler System CWE-639 9.8 Critical 2026-08-19
CVE-2026-73347 WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerability — TrueBooker CWE-266 9.8 Critical 2026-08-19
CVE-2026-16142 TrueBooker <= 1.2.6 - Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter — TrueBooker – Appointment Booking and Scheduler System CWE-639 9.8 Critical 2026-08-15
CVE-2026-14364 TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid' — TrueBooker – Appointment Booking and Scheduler System CWE-640 9.8 Critical 2026-08-07
CVE-2026-14365 TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id' — TrueBooker – Appointment Booking and Scheduler System CWE-862 9.8 Critical 2026-08-07
CVE-2026-13161 TrueBooker <= 1.2.2 - Unauthenticated SQL Injection — TrueBooker – Appointment Booking and Scheduler System CWE-89 7.5 High 2026-07-28
CVE-2026-61951 WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability — TrueBooker CWE-266 9.8 Critical 2026-07-23
CVE-2026-61950 WordPress TrueBooker plugin <= 1.2.3 - SQL Injection vulnerability — TrueBooker CWE-89 9.3 Critical 2026-07-23
CVE-2026-48881 WordPress TrueBooker plugin <= 1.1.9 - Broken Access Control vulnerability — TrueBooker CWE-862 9.1 Critical 2026-06-15
CVE-2026-39663 WordPress TrueBooker plugin <= 1.1.5 - Broken Access Control vulnerability — TrueBooker CWE-862 5.3 Medium 2026-04-08
CVE-2026-1797 Truebooker - Appointment Booking and Scheduler Plugin <= 1.1.4 - Sensitive Information Exposure via Views Files — TrueBooker – Appointment Booking and Scheduler System CWE-862 5.3 Medium 2026-03-31
CVE-2026-32400 WordPress Boldman theme <= 7.7 - Local File Inclusion vulnerability — Boldman CWE-98 7.5 High 2026-03-13
CVE-2025-67581 WordPress TrueBooker plugin <= 1.1.0 - Broken Access Control vulnerability — TrueBooker CWE-862 5.3 Medium 2025-12-09
CVE-2025-47543 WordPress TrueBooker plugin <= 1.0.7 - Cross Site Request Forgery (CSRF) Vulnerability — TrueBooker CWE-352 4.3 Medium 2025-05-07

This page lists every published CVE security advisory associated with themetechmount. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.