A security flaw has been found in the TrueBooker plugin for WordPress, affecting all versions up to and including 1.2.6. This flaw allows anyone without an existing login for your site to change the email address tied to any user account on your WordPress site, including administrator accounts.
Once an attacker changes a site administrator’s email address to one they control, they can use WordPress’s standard password reset feature to receive a password reset link at the attacker’s email. This gives them full access to the administrator account, and complete control over your WordPress site.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-16142