A security vulnerability has been discovered in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress, a tool many service-based businesses use to manage client appointment bookings. All versions of this plugin up to and including version 1.2.6 are affected by this flaw.
The issue allows unauthenticated attackers (people who do not have a valid login for your WordPress site) to change the email address linked to any user account on your site, including administrator accounts. Once an attacker changes an administrator’s email address, they can use the standard WordPress lost password feature to reset the admin account password, giving them full control over your entire website.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18315