Pricing
Case studies
Login
Start trial
TrueBooker
ThemetechMount
Developer
1.2.8
Latest version
600
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
20 patched
12 Mitigation rules
Unauthenticated Appointment and Payment Record Deletion via update_appointment_booked vulnerability
< 1.2.7
21/08/2026
Unauthenticated Account Takeover via Multiple AJAX Actions vulnerability
< 1.2.7
21/08/2026
Unauthenticated Arbitrary Appointment Status Change via update_appointment_status vulnerability
< 1.2.7
21/08/2026
Unauthenticated Customer PII Disclosure via Multiple AJAX Actions vulnerability
< 1.2.7
21/08/2026
Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter vulnerability
<= 1.2.6
20/08/2026
Privilege Escalation vulnerability
<= 1.2.6
19/08/2026
Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter vulnerability
<= 1.2.6
17/08/2026
Missing Authorization to Unauthenticated Arbitrary Password Reset vulnerability
<= 1.2.3
11/08/2026
Missing Authorization to Unauthenticated Arbitrary Password Reset vulnerability
<= 1.2.3
11/08/2026
Unauthenticated SQL Injection vulnerability
<= 1.2.2
31/07/2026
Unauthenticated Account Takeover vulnerability
< 1.2.4
30/07/2026
Privilege Escalation vulnerability
<= 1.2.3
17/07/2026
SQL Injection vulnerability
<= 1.2.3
16/07/2026
Broken Access Control vulnerability
<= 1.1.9
02/06/2026
WordPress Truebooker - Appointment Booking and Scheduler Plugin plugin <= 1.1.4 - Sensitive Information Exposure via Views Files vulnerability
<= 1.1.4
31/03/2026
Broken Access Control vulnerability
<= 1.1.6
18/02/2026
Broken Access Control vulnerability
<= 1.1.0
15/12/2025
Cross Site Request Forgery (CSRF) Vulnerability
<= 1.0.7
07/05/2025
Multiple Unauthenticated SQLi vulnerability
<= 1.0.2
15/08/2024
Settings Update via CSRF vulnerability
<= 1.0.2
15/08/2024