What is CVE-2026-16142?
A critical Account Takeover vulnerability has been found in the TrueBooker plugin for WordPress up to version 1.2.6, allowing unauthenticated users to compromise accounts. The flaw exists in the `add_front_user_update()` AJAX handler, which improperly accepts an arbitrary `truebooker_wp_user_id` value. Immediate update to the latest version is crucial to prevent full site compromise.
Azərbaycanca: WordPress üçün TrueBooker plaqininin 1.2.6 və daha əvvəlki versiyalarında autentifikasiya olunmamış istifadəçilərə hesab ələ keçirməyə (Account Takeover) imkan verən kritik boşluq aşkarlanıb. Zəiflik `add_front_user_update()` AJAX funksiyasının yoxlanılmamış `truebooker_wp_user_id` dəyərini qəbul etməsi ilə bağlıdır. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur, əks halda saytlar tam ələ keçirilə bilər.
FAQ2
What is the root cause of the account takeover vulnerability in the TrueBooker plugin?
The flaw exists in the `add_front_user_update()` AJAX handler, which improperly accepts an arbitrary `truebooker_wp_user_id` value.
Which versions are affected by CVE-2026-16142?
The TrueBooker plugin for WordPress up to version 1.2.6 is affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.