SQL Injection Vulnerability in TrueBooker Appointment Booking and Scheduler System for WordPress
CVE-2026-13161
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-13161?
The TrueBooker Appointment Booking and Scheduler System plugin for WordPress is susceptible to a SQL Injection flaw due to inadequate user input sanitization, specifically within the 'alldata[truebooker_user]' parameter. This oversight is prevalent in all versions up to and including 1.2.2. Attackers without authentication can exploit this vulnerability by injecting rogue SQL commands into existing queries, potentially exposing sensitive database information. Furthermore, the nonce generated by check_ajax_referer() does not enhance security, as it remains accessible to unauthenticated users on booking pages. Successful exploitation necessitates specific booking fields to be included in the alldata POST parameter, allowing the attack to reach the vulnerable SQL execution point.
Affected Version(s)
TrueBooker β Appointment Booking and Scheduler System 0 <= 1.2.2