CVE-2026-16142 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 04:05am

A security flaw has been identified in the TrueBooker plugin for WordPress, impacting all versions up to and including 1.2.6. The vulnerability allows unauthenticated visitors (people who are not logged into your WordPress site) to modify the email address associated with any user account on your site, including administrator accounts, with no verification that they have permission to make this change.

Once an attacker updates a target account's email to an address they control, they can use WordPress's standard password reset process to receive a reset link at the attacker-controlled email. This grants them full control of the compromised account, which could lead to unauthorized changes to your site, access to sensitive information, or other malicious activity.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-16142

« Back