A security vulnerability (tracked as CVE-2026-16142) impacts the TrueBooker plugin for WordPress, with all versions of the plugin up to and including 1.2.6 affected.
This flaw allows anyone who is not logged into your WordPress site to change the email address linked to any user account on the site, including administrator accounts. An attacker only needs to submit the target user's ID and an email address they control to make this change, with no requirement to prove they own the original account.
Once the email address is swapped, the attacker can use WordPress's standard password reset feature to get a password reset link sent to their own email address, letting them take full control of the targeted account.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-16142