CVE-2026-16142 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 16:05pm

A security vulnerability has been discovered in the TrueBooker plugin for WordPress, affecting all versions up to and including 1.2.6.

This flaw allows unauthenticated users (people who are not logged into your site) to change the email address for any user account on your WordPress site, including administrator accounts. After an attacker updates the account email to an address they control, they can use WordPress’s standard password reset flow to receive a reset link at their own email, granting them full control of the compromised account.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-16142

« Back