CVE-2026-18776: CWE-269 Improper Privilege Management in TrueBooker
CVE-2026-18776 is a critical vulnerability in the TrueBooker WordPress plugin versions before 1.2.7. It involves improper authorization checks in certain AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators. This flaw enables attackers to take over accounts by exploiting the password reset process.
AI Analysis
Technical Summary
The TrueBooker WordPress plugin prior to version 1.2.7 lacks proper authorization validation on some AJAX endpoints. This weakness permits unauthenticated attackers to modify the email addresses of any user, including administrators. By changing the email address, attackers can trigger the password reset flow to gain control over the targeted accounts. The vulnerability is classified under CWE-269 (Improper Privilege Management) and CWE-284 (Improper Access Control). It has a CVSS v3.1 score of 9.8, indicating a critical severity with network attack vector, no privileges required, no user interaction, and full confidentiality, integrity, and availability impact.
Potential Impact
Successful exploitation allows unauthenticated attackers to hijack user accounts, including administrator accounts, by changing their email addresses and resetting passwords. This leads to complete compromise of affected user accounts and potentially the entire WordPress site managed by the TrueBooker plugin.
Mitigation Recommendations
Upgrade the TrueBooker plugin to version 1.2.7 or later, where proper authorization checks have been implemented to prevent unauthorized email address changes via AJAX actions. No other mitigations are specified. Patch status is confirmed by the existence of fixed version 1.2.7.
CVE-2026-18776: CWE-269 Improper Privilege Management in TrueBooker
Description
CVE-2026-18776 is a critical vulnerability in the TrueBooker WordPress plugin versions before 1.2.7. It involves improper authorization checks in certain AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators. This flaw enables attackers to take over accounts by exploiting the password reset process.
CVSS v3.1
Score 9.8critical
Affected software
TrueBooker
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The TrueBooker WordPress plugin prior to version 1.2.7 lacks proper authorization validation on some AJAX endpoints. This weakness permits unauthenticated attackers to modify the email addresses of any user, including administrators. By changing the email address, attackers can trigger the password reset flow to gain control over the targeted accounts. The vulnerability is classified under CWE-269 (Improper Privilege Management) and CWE-284 (Improper Access Control). It has a CVSS v3.1 score of 9.8, indicating a critical severity with network attack vector, no privileges required, no user interaction, and full confidentiality, integrity, and availability impact.
Potential Impact
Successful exploitation allows unauthenticated attackers to hijack user accounts, including administrator accounts, by changing their email addresses and resetting passwords. This leads to complete compromise of affected user accounts and potentially the entire WordPress site managed by the TrueBooker plugin.
Mitigation Recommendations
Upgrade the TrueBooker plugin to version 1.2.7 or later, where proper authorization checks have been implemented to prevent unauthorized email address changes via AJAX actions. No other mitigations are specified. Patch status is confirmed by the existence of fixed version 1.2.7.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-08-04T07:43:29.649Z
- State
- PUBLISHED
Threat ID: 6a854e93c6e8be033248b293
Added to database: 08/19/2026, 06:34:59 UTC
Last enriched: 09/11/2026, 09:47:29 UTC
Last updated: 10/03/2026, 07:26:58 UTC
Views: 70
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.