WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in TrueBooker – Appointment Booking and Scheduler System

Book appointments, create booking with TrueBooker. Easily create appointments, manage time and dates and send out emails.

17Reported vulnerabilities
9.8Highest CVSS score
1.2.8Latest version
600+Active installs

What to do now

Update TrueBooker – Appointment Booking and Scheduler System to 1.2.7 or later. 17 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 17, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2026-18315 Critical 9.8 0.6% 0 to 1.2.6 (inclusive) 1.2.7 August 19, 2026
CVE-2026-16142 Critical 9.8 0.4% 0 to 1.2.6 (inclusive) 1.2.7 August 15, 2026
CVE-2026-14365 Critical 9.8 0.3% 0 to 1.2.3 (inclusive) 1.2.4 August 7, 2026
CVE-2026-14364 Critical 9.8 0.3% 0 to 1.2.3 (inclusive) 1.2.4 August 7, 2026
CVE-2026-61951 Critical 9.8 0.5% 1.2.3 and earlier 1.2.4 July 17, 2026
CVE-2026-13161 High 7.5 0.5% 0 to 1.2.2 (inclusive) 1.2.3 July 28, 2026
CVE-2026-61950 High 7.5 0.4% 1.2.3 and earlier 1.2.4 July 16, 2026
CVE-2026-18776 High 7.3 0.3% Before 1.2.7 1.2.7 August 21, 2026
CVE-2026-73347 High 7.3 0.3% 1.2.6 and earlier 1.2.7 August 19, 2026
CVE-2026-18777 Medium 5.3 0.2% Before 1.2.7 1.2.7 August 21, 2026
CVE-2026-18778 Medium 5.3 0.3% Before 1.2.7 1.2.7 August 21, 2026
CVE-2026-18779 Medium 5.3 0.2% Before 1.2.7 1.2.7 August 21, 2026
CVE-2026-48881 Medium 5.3 0.3% 1.1.9 and earlier 1.2.0 June 2, 2026
CVE-2026-1797 Medium 5.3 0.2% 0 to 1.1.4 (inclusive) 1.1.5 March 31, 2026
CVE-2026-39663 Medium 5.3 0.2% 1.1.6 and earlier 1.1.7 February 18, 2026
CVE-2025-67581 Medium 5.3 0.2% 1.1.0 and earlier 1.1.1 December 15, 2025
CVE-2025-47543 Medium 4.3 0.2% 1.0.7 and earlier 1.0.8 May 7, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.