{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/truebooker--appointment-booking-and-scheduler-system-plugin/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-13161"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TrueBooker – Appointment Booking and Scheduler System plugin","WordPress"],"_cs_severities":["high"],"_cs_tags":["wordpress","sqli","plugin","web-vulnerability","cve"],"_cs_type":"advisory","_cs_vendors":["TrueBooker","WordPress Foundation"],"content_html":"\u003cp\u003eCVE-2026-13161 identifies a critical SQL Injection vulnerability within the TrueBooker - Appointment Booking and Scheduler System plugin for WordPress, impacting all versions up to and including 1.2.2. This flaw stems from insufficient input sanitization of the \u003ccode\u003ealldata[truebooker_user]\u003c/code\u003e parameter and inadequate preparation of the existing SQL query. The vulnerability allows unauthenticated attackers to append malicious SQL queries to existing database queries, potentially leading to the extraction of sensitive information. Although the \u003ccode\u003echeck_ajax_referer()\u003c/code\u003e nonce guard is present, it does not prevent exploitation as the required nonce is publicly exposed on TrueBooker's front-end booking pages to unauthenticated visitors. Successful exploitation requires the attacker to include specific booking fields (category, service, person, date, and time slot) within the \u003ccode\u003ealldata\u003c/code\u003e POST parameter to reach the vulnerable code path.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eReconnaissance\u003c/strong\u003e: An unauthenticated attacker identifies a WordPress site utilizing the vulnerable TrueBooker - Appointment Booking and Scheduler System plugin (version 1.2.2 or earlier).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNonce Collection\u003c/strong\u003e: The attacker accesses a front-end booking page served by the TrueBooker plugin to retrieve a valid anti-CSRF nonce value, which is exposed in the page's source code.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePayload Crafting\u003c/strong\u003e: The attacker crafts a malicious HTTP POST request to a TrueBooker AJAX endpoint, including the previously collected nonce and all required booking fields (category, service, person, date, time slot) within the \u003ccode\u003ealldata\u003c/code\u003e POST parameter.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eSQL Injection\u003c/strong\u003e: Within the \u003ccode\u003ealldata[truebooker_user]\u003c/code\u003e sub-parameter of the POST request, the attacker embeds an SQL injection payload designed to manipulate the database query (e.g., \u003ccode\u003eUNION SELECT\u003c/code\u003e statements).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eExploitation Attempt\u003c/strong\u003e: The crafted POST request is sent to the vulnerable endpoint, triggering the plugin's logic to process the booking parameters.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eMalicious Query Execution\u003c/strong\u003e: Due to insufficient escaping and preparation, the plugin concatenates the attacker's SQL injection payload directly into a database query. The database then executes this manipulated query.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eData Extraction\u003c/strong\u003e: The executed malicious query causes the database to return sensitive information (e.g., user hashes, system configurations, private data) in the HTTP response, which the attacker collects.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-13161 allows unauthenticated attackers to extract arbitrary sensitive information directly from the compromised WordPress database. This can include user credentials, personal data of clients, website configuration details, or other proprietary information stored within the database. The ease of exploitation, given the public exposure of the nonce and unauthenticated nature, makes this a high-risk vulnerability, potentially leading to significant data breaches and further compromise of the WordPress installation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-13161 by updating the TrueBooker - Appointment Booking and Scheduler System plugin to version 1.2.3 or higher immediately on all affected WordPress installations.\u003c/li\u003e\n\u003cli\u003eMonitor \u003ccode\u003ewebserver\u003c/code\u003e access logs for \u003ccode\u003ePOST\u003c/code\u003e requests containing common SQL injection characters in the \u003ccode\u003ecs-uri-query\u003c/code\u003e or \u003ccode\u003ecs-raw-body\u003c/code\u003e fields, especially targeting \u003ccode\u003eadmin-ajax.php\u003c/code\u003e or other plugin-related endpoints.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detects CVE-2026-13161 Exploitation - TrueBooker WordPress SQLi\u0026quot; to your SIEM and tune for your environment, paying close attention to \u003ccode\u003ecs-uri-query\u003c/code\u003e patterns.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T09:20:07Z","date_published":"2026-07-28T09:20:07Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-13161-truebooker-sqli/","summary":"An unauthenticated attacker can exploit CVE-2026-13161, a generic SQL Injection vulnerability in the TrueBooker - Appointment Booking and Scheduler System plugin for WordPress affecting versions up to and including 1.2.2, by manipulating the 'alldata[truebooker_user]' parameter in POST requests, allowing the extraction of sensitive database information.","title":"TrueBooker WordPress Plugin SQL Injection Vulnerability (CVE-2026-13161)","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-13161-truebooker-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - TrueBooker – Appointment Booking and Scheduler System Plugin","version":"https://jsonfeed.org/version/1.1"}