A security vulnerability has been found in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress, affecting all versions up to and including 1.2.6. The issue is an authorization bypass caused by a specific plugin tool not requiring any login or permission verification before processing user-supplied input.
This gap allows unauthenticated attackers (people who do not have valid login credentials for your site) to change the email address associated with any user on your WordPress site, including administrator accounts. After modifying the email, attackers can use WordPress’s standard lost password feature to gain full control of the targeted account, which could lead to complete compromise of your site.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18315