What is CVE-2026-18315?
This CVE describes an Authorization Bypass Through User-Controlled Key vulnerability in the TrueBooker plugin for WordPress (up to version 1.2.6). The issue stems from the lack of authentication in the 'admin_user_create_cus' AJAX handler, potentially leading to Account Takeover. Users should immediately update to the latest version or temporarily disable the plugin.
Azərbaycanca: Bu CVE, WordPress üçün TrueBooker plaginində (versiya 1.2.6 və aşağısı) "Authorization Bypass Through User-Controlled Key" zəifliyidir. Bu, autentifikasiya olunmamış "admin_user_create_cus" AJAX handleri vasitəsilə hesab ələ keçirməyə (Account Takeover) səbəb ola bilər. İstifadəçilər plaqini dərhal ən son versiyaya yeniləməli və ya müvəqqəti olaraq deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the TrueBooker plugin are affected by CVE-2026-18315?
CVE-2026-18315 affects the TrueBooker plugin for WordPress up to and including version 1.2.6.
What should I do to protect against CVE-2026-18315?
You should immediately update the TrueBooker plugin to the latest version, or temporarily disable the plugin if an update is not possible.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.