CVE-2026-1797Disclosure

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 through views php files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed views php files via direct access.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-31); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-31: 2Mentions · 2026-04-01: 1PoC Mentioned / Linked · 2026-04-01: 1Technical Details · 2026-03-31: 203-3104-01
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-312
Disclosure2
2026-04-011
PoC1
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-1797-truebooker-appointment-booking-version-1-1-4-medium-vulnerability-proof-of-concept CVE-2026-1797 #WordPress plugin #vulnerability truebooker-appointment-booking#cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecuri…

    Post summary

    The post shares a proof‑of‑concept for CVE‑2026‑1797 targeting the TrueBooker WordPress plugin; it does not include active exploitation evidence, patch information, or detailed technical vulnerability data.

    0000054
    5 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1797 The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1… https://www.cve.org/CVERecord?id=CVE-2026-1797

    Post summary

    The CVE-2026-1797 entry discloses that the Truebooker WordPress plugin is vulnerable to sensitive information exposure, but offers no evidence of exploitation, PoC, or available patch information.

    0000067
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-1797 - Truebooker - Appointment Booking and Scheduler Plugin <= 1.1.4 - Sensitive Information Exposure via Views Files Intel Report: https://ift.tt/7KS9Unf

    Post summary

    A threat alert has been issued for CVE-2026-1797 affecting Truebooker versions up to 1.1.4, highlighting a sensitive information exposure issue through view files.

    0000037
    281 followersView on X

Explore more