{"api_version":"1","generated_at":"2026-08-19T11:43:50+00:00","cve":"CVE-2026-18779","urls":{"html":"https://cve.report/CVE-2026-18779","api":"https://cve.report/api/cve/CVE-2026-18779.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-18779","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-18779"},"summary":{"title":"TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appointment and Payment Record Deletion via update_appointment_booked","description":"The TrueBooker  WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-19 06:17:38","updated_at":"2026-08-19 06:17:38"},"problem_types":["CWE-862 Missing Authorization"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/9d7f9a09-a144-4a0a-998c-e5bc5037fc1b/","name":"https://wpscan.com/vulnerability/9d7f9a09-a144-4a0a-998c-e5bc5037fc1b/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-18779","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18779","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"TrueBooker","version":"affected 1.2.7 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Erwan LR (WPScan)","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"TrueBooker","vendor":"Unknown","versions":[{"lessThan":"1.2.7","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Erwan LR (WPScan)"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The TrueBooker  WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records."}],"problemTypes":[{"descriptions":[{"description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-19T06:00:20.143Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/9d7f9a09-a144-4a0a-998c-e5bc5037fc1b/"}],"source":{"discovery":"EXTERNAL"},"title":"TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appointment and Payment Record Deletion via update_appointment_booked","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-18779","datePublished":"2026-08-19T06:00:20.143Z","dateReserved":"2026-08-04T07:48:52.358Z","dateUpdated":"2026-08-19T06:00:20.143Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-19 06:17:38","lastModifiedDate":"2026-08-19 06:17:38","problem_types":["CWE-862 Missing Authorization"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"18779","Ordinal":"1","Title":"TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appoint","CVE":"CVE-2026-18779","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"18779","Ordinal":"1","NoteData":"The TrueBooker  WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records.","Type":"Description","Title":"TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appoint"}]}}}