CVE-2026-18776: TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Account Takeover via Multiple AJAX Actions
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their account via the password reset flow.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated user can exploit the affected AJAX actions. No existing WordPress account is required.
What is required for account takeover?
An attacker must be able to change a target user's email address through the vulnerable AJAX actions, then use the normal password reset flow to reset that user's password. Administrator accounts are included among the potential targets.
Which installations are affected?
TrueBooker Appointment Booking versions before 1.2.7 are affected. The available information does not state whether any particular configuration or feature state is required.