CVE-2026-18315

Published: Ago 19, 2026 Last Modified: Ago 19, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,8
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including, 1.2.6. This is due to the admin_user_create_cus AJAX handler lacking any authentication or capability check before passing the attacker-supplied truebooker_wp_user_id parameter directly to wp_update_user. This makes it possible for unauthenticated attackers to overwrite the email address of any WordPress user — including an administrator — and then complete the standard WordPress lost-password flow to fully take over the targeted account.

639

Authorization Bypass Through User-Controlled Key

Incomplete
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
https://plugins.svn.wordpress.org/truebooker-appointment-booking/tags/1.2.6/mai…
https://plugins.svn.wordpress.org/truebooker-appointment-booking/tags/1.2.6/mai…
https://plugins.svn.wordpress.org/truebooker-appointment-booking/tags/1.2.6/tem…
https://plugins.trac.wordpress.org/changeset/3640018/truebooker-appointment-boo…
https://www.wordfence.com/threat-intel/vulnerabilities/id/73251a74-5be3-446b-8e…