A security flaw has been found in the TrueBooker plugin for WordPress, affecting all versions up to and including 1.2.6. This vulnerability lets unauthenticated users (people who do not have a login for your site) take over any user account on your WordPress site, including administrator accounts.
The plugin has a feature meant to let users update their account information, but it is not secured to verify that the person using the feature is authorized to make changes to the account they are targeting. An attacker can select any user account on your site, change its registered email address to one they control, then use the standard WordPress "forgot password" tool to get a password reset link sent to that attacker-owned email. They can then use that link to set a new password and access the account as if they were the legitimate owner.
If an attacker gains access to an administrator account, they may be able to change your site's content, access private customer or business data, add harmful software to your site, or lock you out of your own WordPress dashboard entirely.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-16142