CVE-2026-18315
CRITICAL
9,8
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including, 1.2.6. This is due to the admin_user_create_cus AJAX handler lacking any authentication or capability check before passing the attacker-supplied truebooker_wp_user_id parameter directly to wp_update_user. This makes it possible for unauthenticated attackers to overwrite the email address of any WordPress user — including an administrator — and then complete the standard WordPress lost-password flow to fully take over the targeted account.
639
Authorization Bypass Through User-Controlled Key
IncompleteCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
https://plugins.svn.wordpress.org/truebooker-appointment-booking/tags/1.2.6/mai…
https://plugins.svn.wordpress.org/truebooker-appointment-booking/tags/1.2.6/mai…
https://plugins.svn.wordpress.org/truebooker-appointment-booking/tags/1.2.6/tem…
https://plugins.trac.wordpress.org/changeset/3640018/truebooker-appointment-boo…
https://www.wordfence.com/threat-intel/vulnerabilities/id/73251a74-5be3-446b-8e…