CVE-2026-1797 identifies a Sensitive Information Exposure vulnerability in all versions up to and including 1.1.4 of the Truebooker – Appointment Booking and Scheduler Plugin for WordPress. This medium-severity flaw (CVSS 5.3) allows unauthenticated attackers to view potentially sensitive information by directly accessing exposed views PHP files, requiring no privileges or user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community attention, and it is not listed on CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Themetechmount | TrueBooker – Appointment Booking And Scheduler System | >= 0, <= 1.1.4CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.