SQL Injection Vulnerability in TrueBooker Appointment Booking and Scheduler System for WordPress
CVE-2026-13161

7.5HIGH

What is CVE-2026-13161?

The TrueBooker Appointment Booking and Scheduler System plugin for WordPress is susceptible to a SQL Injection flaw due to inadequate user input sanitization, specifically within the 'alldata[truebooker_user]' parameter. This oversight is prevalent in all versions up to and including 1.2.2. Attackers without authentication can exploit this vulnerability by injecting rogue SQL commands into existing queries, potentially exposing sensitive database information. Furthermore, the nonce generated by check_ajax_referer() does not enhance security, as it remains accessible to unauthenticated users on booking pages. Successful exploitation necessitates specific booking fields to be included in the alldata POST parameter, allowing the attack to reach the vulnerable SQL execution point.

Affected Version(s)

TrueBooker – Appointment Booking and Scheduler System 0 <= 1.2.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Karan J
.