CRITICAL 9.8 CVE-2026-18315 Published 19 Aug 2026

WordPress TrueBooker Plugin Authorization Bypass

Worried this affects one of your servers?

The TrueBooker plugin for WordPress is vulnerable to an Authorization Bypass Through User-Controlled Key leading to Account Takeover.

TrueBooker versions up to 1.2.6 are affected. This is due to the admin_user_create_cus AJAX handler lacking authentication or capability checks.

Unauthenticated attackers can overwrite any WordPress user's email address, including administrators, and take over the account.

Reference: CVE-2026-18315 on NVD

← Back to Security News