CVE-2026-16142 (matched: wordpress)

  • Saturday, 15th August, 2026
  • 22:05pm

A security flaw has been identified in the TrueBooker plugin for WordPress, impacting all versions of the tool up to and including 1.2.6. The issue allows anyone who is not logged into your website to change the email address linked to any user account on your WordPress site, including administrator accounts.

Once an attacker changes an administrator’s email address to one they control, they can use WordPress’s standard password reset feature to receive a password reset link at that external email. This lets them take full control of the administrator account, and gain access to your website.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-16142

« Back