Missing Authorization in TrueBooker Appointment Booking by Themotechmount
CVE-2026-39663
5.3MEDIUM
What is CVE-2026-39663?
A missing authorization vulnerability exists in the TrueBooker appointment booking plugin developed by Themotechmount, allowing attackers to exploit incorrectly configured access control security levels. This significant issue affects versions of TrueBooker from an unknown starting point up to and including 1.1.5, potentially exposing sensitive functionality to unauthorized users.
Affected Version(s)
TrueBooker 0 <= 1.1.5