A security vulnerability has been identified in the TrueBooker plugin for WordPress, a tool some site owners use to manage booking functionality. All versions of the plugin up to and including version 1.2.6 are affected by this flaw.
The issue allows anyone without a valid login to your WordPress site to change the email address linked to any user account on your site, including administrator accounts. Attackers can exploit this by sending a specially crafted request to the plugin's public booking tool, providing the ID of the target user account and an email address they control, with no authentication required.
Once an attacker has changed a user's email to one they control, they can use WordPress's built-in password reset feature to receive a password reset link at the attacker's email address. This gives them full control of the compromised account, including access to all site settings, content, and data associated with that user.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-16142