CVE-2026-18315 (matched: wordpress)

  • Wednesday, 19th August, 2026
  • 22:05pm

A security flaw has been identified in the TrueBooker – Appointment Booking and Scheduler plugin for WordPress, a tool used to manage appointment booking requests on websites. This issue impacts all versions of the plugin up to and including 1.2.6. The flaw exists because the plugin's account creation feature does not verify that the person using it has the required permissions, letting unauthenticated attackers (people who do not have a valid login for your website) overwrite the email address tied to any user account on your WordPress site, including administrator accounts. Attackers can then use the standard WordPress "lost password" feature to gain full control of the targeted account. If an attacker takes over an administrator account, they can change your site’s content, access private visitor or customer data, or use your website to send spam or malware to other people.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18315

« Back