A security vulnerability has been discovered in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress. All versions of this plugin up to and including version 1.2.6 are impacted by this flaw.
The issue allows unauthenticated attackers (people who do not have a valid login for your site) to bypass the plugin's access controls. These bad actors can change the email address linked to any user account on your WordPress site, including administrator accounts.
After modifying an administrator's email address, attackers can use WordPress's standard lost password feature to reset the admin account's password. This grants the attacker full control over your website.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18315