CVE-2026-1797

MEDIUM

Truebooker - Appointment Booking and Scheduler Plugin <= 1.1.4 - Sensitive Information Exposure via Views Files

Title source: cna
STIX 2.1

Description

The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 through views php files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed views php files via direct access.

Scores

CVSS v3 5.3
EPSS 0.0021
EPSS Percentile 10.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
themetechmount/Truebooker – Appointment Booking and Scheduler System < 1.1.4
themetechmount/TrueBooker – Appointment Booking and Scheduler System < 1.1.4
Published Mar 31, 2026
Tracked Since Mar 31, 2026