CRITICAL
9.8 CVE-2026-18315 Published 19 Aug 2026
WordPress TrueBooker Plugin Authorization Bypass
Worried this affects one of your servers?
The TrueBooker plugin for WordPress is vulnerable to an Authorization Bypass Through User-Controlled Key leading to Account Takeover.
TrueBooker versions up to 1.2.6 are affected. This is due to the admin_user_create_cus AJAX handler lacking authentication or capability checks.
Unauthenticated attackers can overwrite any WordPress user's email address, including administrators, and take over the account.
Reference: CVE-2026-18315 on NVD
← Back to Security News