Summary
CVE-2026-13161 is a high-severity unauthenticated SQL injection vulnerability in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress, affecting all versions up to and including 1.2.2. Due to insufficient escaping of user-supplied input and improper SQL query preparation, unauthenticated remote attackers can inject arbitrary SQL commands via the alldata[truebooker_user] POST parameter to extract sensitive data from the WordPress database. The vulnerability carries a CVSS v3.1 score of 7.5 (HIGH).
Technical details
- Root cause: The
alldata[truebooker_user]POST parameter is insufficiently escaped before being incorporated into existing SQL queries, and those queries lack proper preparation (CWE-89). This allows an attacker to append arbitrary SQL statements to the existing query. - Nonce bypass: The plugin’s
check_ajax_referer()nonce guard does not constitute an authentication or authorization barrier. The nonce value is exposed to unauthenticated visitors on TrueBooker’s public-facing booking pages, rendering it ineffective as a security control against this attack. - Trigger conditions: Exploitation requires that the booking fields — category, service, person, date, and time slot — be present in the
alldataPOST parameter so that execution reaches the vulnerable SQL query branch. These are functional prerequisites, not authentication barriers, and can be supplied programmatically by an attacker with no special access. - Attack vector: Unauthenticated HTTP POST request over the network to a WordPress AJAX endpoint. No credentials, local access, or user interaction are required (AV:N, AC:L, PR:N, UI:N).
- Impact: High confidentiality impact (C:H). A successful attack enables extraction of arbitrary data from the WordPress database, which typically contains user credentials, personal information, and site configuration data.
Affected software
- TrueBooker – Appointment Booking and Scheduler System (WordPress plugin by themetechmount), all versions up to and including 1.2.2
Severity
CVSS v3.1 Base Score: 7.5 (HIGH)
Vector string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate action: Update the TrueBooker plugin to version 1.2.3 or later. Version 1.2.3 introduced fixes for input validation and database query handling in the affected AJAX handler. The current latest release is 1.2.6. Updates can be applied directly from the WordPress admin dashboard under Plugins → Installed Plugins.
- If immediate patching is not possible: Consider restricting unauthenticated access to the WordPress AJAX endpoint (
/wp-admin/admin-ajax.php) via web application firewall rules or network-layer controls as a temporary compensating measure, accepting that this may disrupt front-end booking form functionality.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

