A security flaw has been identified in the TrueBooker plugin for WordPress, impacting all versions of the plugin up to and including version 1.2.6. The issue allows anyone who visits your website, even if they are not logged in or have an account with you, to change the email address linked to any user on your WordPress site, including your primary administrator account.
Once an attacker updates an administrator’s email to an address they control, they can use WordPress’s built-in password reset feature to receive a reset link at their own email. This grants them full access to the administrator account, and therefore full control of your website and all its content.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-16142