Summary
CVE-2026-73347 is a critical unauthenticated privilege escalation vulnerability in the TrueBooker – Appointment Booking and Scheduler System WordPress plugin, affecting all versions up to and including 1.2.6. The flaw is classified as CWE-266 (Incorrect Privilege Assignment) and carries a CVSS v3.1 base score of 9.8 (Critical), as it allows a remote, unauthenticated attacker to escalate privileges without any user interaction.
Technical details
- Root cause: The plugin incorrectly assigns or fails to properly restrict privilege levels within its user-handling logic, classified under CWE-266 (Incorrect Privilege Assignment).
- Trigger conditions: No authentication or user interaction is required to exploit the flaw.
- Attack vector: Network — the vulnerability is remotely exploitable over HTTP(S) against any internet-facing WordPress site running the affected plugin.
- Impact: Successful exploitation allows an unauthenticated attacker to escalate privileges, which can lead to full compromise of confidentiality, integrity, and availability of the affected WordPress site.
Affected software
- TrueBooker – Appointment Booking and Scheduler System (WordPress plugin, slug:
truebooker-appointment-booking) — versions ≤ 1.2.6
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade the TrueBooker plugin to version 1.2.7 or later, which resolves the privilege escalation issue.
- If immediate patching is not possible: Restrict or disable public access to the plugin’s booking/user-management functionality, and monitor for unexpected privilege changes or new administrative accounts as a compensating control until the update can be applied.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
/wp-content/plugins/truebooker-appointment-booking/

