CVE-2026-18315 (matched: wordpress)

  • Friday, 21st August, 2026
  • 16:05pm

A security flaw has been identified in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress, which impacts all versions of the plugin up to and including 1.2.6. This issue allows unauthenticated attackers (people who do not have valid login credentials for your website) to exploit a gap in the plugin's account management functions.

The flaw lets these attackers overwrite the email address linked to any user on your WordPress site, including administrator accounts. Once an attacker changes an administrator's email address, they can use the standard WordPress "lost password" feature to reset the account's password and gain full, unrestricted access to the targeted account and your site's backend.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18315

« Back