CVE-2026-39663 is a missing authorization vulnerability in themetechmount TrueBooker appointment booking plugin versions up to 1.1.5, stemming from incorrectly configured access control security levels. The flaw allows unauthorized actions to be performed against the application without proper privilege verification. The vulnerability has a CVSS v3.1 score of 5.3 (Medium) with a network-based attack vector requiring no authentication or user interaction. Attack complexity is low, meaning exploitation requires minimal effort. The primary impact is integrity compromise, while confidentiality and availability remain unaffected. There is currently no evidence of active exploitation in the wild. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and is inactive on threat tracking lists. With an EPSS score of 0.00037 and a FAUCET risk score of 32.0/100, the immediate threat level remains low, though the authorization flaw warrants timely patching to prevent potential abuse.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.1.5CPE match | cpe:2.3:a:themetechmount:truebooker:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.