Themetechmount

Truebooker

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 31.03.2026 05:16:10
  • Zuletzt bearbeitet 24.04.2026 18:11:16

The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 through views php files. This makes it possible for unauthenticated attackers t...

  • EPSS 0.2%
  • Veröffentlicht 09.12.2025 14:14:15
  • Zuletzt bearbeitet 27.04.2026 18:16:44

Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TrueBooker: from n/a through <= 1.1.0.

  • EPSS 0.16%
  • Veröffentlicht 07.05.2025 14:20:15
  • Zuletzt bearbeitet 23.04.2026 15:30:27

Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Cross Site Request Forgery.This issue affects TrueBooker: from n/a through <= 1.0.7.

Exploit
  • EPSS 3.29%
  • Veröffentlicht 08.09.2024 06:15:02
  • Zuletzt bearbeitet 11.09.2024 16:15:30

The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

Exploit
  • EPSS 0.23%
  • Veröffentlicht 08.09.2024 06:15:02
  • Zuletzt bearbeitet 11.09.2024 16:12:24

The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.