CVE-2026-18777: TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointment Status Change via update_appointment_status
Published Aug 19, 2026
·Updated
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger notification emails to the affected customers.
Affected Software
1 affected component
TrueBooker WordPress plugin "TrueBooker Appointment Booking"<1.2.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TrueBooker Appointment Booking (WordPress plugin)to a version that resolves this vulnerability.Fixed in 1.2.7Patch TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointment Status Change via update_appointment_status
Event History
Aug 19, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Unauthenticated users can exploit the affected AJAX action; no login is required.
2
What can an attacker do if they exploit it?
An attacker can change the status of arbitrary appointments and trigger notification emails to the affected customers.
3
Which installations are affected?
TrueBooker Appointment Booking versions earlier than 1.2.7 are affected.