What is CVE-2026-18776?
The TrueBooker WordPress plugin before version 1.2.7 lacks proper authorization checks in some AJAX actions. This vulnerability allows unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their accounts via the password reset flow. Updating the plugin to version 1.2.7 is strongly recommended.
Azərbaycanca: TrueBooker WordPress plaqinində 1.2.7-dən əvvəlki versiyalarda bəzi AJAX əməliyyatlarında düzgün avtorizasiya yoxlanışı yoxdur. Bu zəiflik autentifikasiya olunmamış istifadəçilərə ixtiyari istifadəçilərin, o cümlədən administratorların e-poçt ünvanlarını dəyişməyə və parol sıfırlama axını vasitəsilə hesabları ələ keçirməyə imkan verir. Plaqini dərhal 1.2.7 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What does the CVE-2026-18776 vulnerability in the TrueBooker WordPress plugin allow?
The vulnerability allows unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their accounts via the password reset flow due to lack of proper authorization checks in some AJAX actions.
How can the CVE-2026-18776 vulnerability be fixed?
Updating the TrueBooker plugin to version 1.2.7 is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.