CVE-2026-18315 (matched: wordpress)

  • Friday, 21st August, 2026
  • 10:08am

A security flaw has been identified in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress, impacting all versions up to and including 1.2.6. The vulnerability allows anyone who does not already have a login account for your WordPress site to change the email address associated with any user account on your site, including administrator accounts. Attackers can exploit this gap by using the standard WordPress lost password feature to reset the targeted account’s password and gain full control of it. If an attacker takes over an administrator account, they can make unrestricted changes to your website, including altering or deleting your content, accessing sensitive customer information, or adding harmful code to your site.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18315

« Back