A security vulnerability has been identified in the TrueBooker plugin for WordPress, impacting all versions up to and including version 1.2.6. The flaw stems from a user update tool built into the plugin being accessible to unauthenticated visitors (people who do not have a login for your site) with no checks to confirm the person submitting changes has permission to edit the target account.
This allows attackers to change the email address associated with any WordPress user on your site, including administrator accounts, by providing the ID number of the user they want to target and an email address they control. Once an attacker modifies an administrator’s email to their own, they can use the standard WordPress password reset flow to receive a reset link at the attacker-controlled address, granting them full control of the affected account and your website.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-16142