CVE-2026-18777

Published: Ago 19, 2026 Last Modified: Ago 19, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger notification emails to the affected customers.

https://wpscan.com/vulnerability/05a09ba7-b781-4462-8c50-3a45f2757cb2/