A security vulnerability, tracked as CVE-2026-16142, has been found in the TrueBooker plugin for WordPress, affecting all versions of the plugin up to and including 1.2.6. This flaw allows anyone to access your site, even without being logged in or having authorized access, to change the email address linked to any user account on your WordPress site, including administrator accounts.
Once an attacker changes the email address for a targeted account, they can use WordPress’s built-in password reset feature to receive a password reset link at the email address they control. This grants them full access to the compromised account.
If an attacker takes control of an administrator account, they can modify your site’s content, steal visitor data, add malicious code, or lock you out of your website entirely.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-16142