LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-18776

Published
CVSS9.8
Severitycritical
WeaknessCWE-284
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their account via the password reset flow.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-18776

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-18776.