CRITICAL 9.8 CVE-2026-18776 Published 19 Aug 2026

WordPress TrueBooker Plugin Unauthenticated User Takeover

Worried this affects one of your servers?

The TrueBooker WordPress plugin, versions prior to 1.2.7, has a critical security vulnerability. It lacks proper authorization checks in certain AJAX actions, allowing unauthenticated users to change the email address of any user, including administrators.

Exploiting this vulnerability, an attacker can take over any user's account, including administrators, by resetting their password via the password reset flow.

Reference: CVE-2026-18776 on NVD

← Back to Security News