WORDPRESS · AUGUST 2026 · EARLY WARNING

TrueBooker WordPress Plugin Vulnerable to Account Takeover

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.8
Affected component
truebooker plugin (wordpress)
Patched version
Not yet available
CVE-2026-16142

An early warning has been issued for a critical vulnerability in the TrueBooker WordPress plugin. Versions up to and including 1.2.6 are reportedly affected.

What happened

The TrueBooker plugin for WordPress is under investigation for a critical vulnerability that could lead to account takeover. This is due to the add_front_user_update() AJAX handler being accessible to unauthenticated users and accepting an arbitrary truebooker_wp_user_id value, which is passed directly to wp_update_user() without verifying authentication or ownership. The vulnerability has been assigned the identifier CVE-2026-16142 with a CVSS score of 9.8, indicating a critical severity level.

There is no evidence at this time that the vulnerability has been exploited in the wild. However, given the severity and potential impact, it is crucial for users of the TrueBooker plugin to assess their exposure and take appropriate action.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If truebooker plugin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using the TrueBooker plugin for WordPress and your version is 1.2.6 or earlier, you are reportedly affected.

What should I do right now?

Review your WordPress installation to determine if you are using an affected version of the TrueBooker plugin. Monitor official sources for updates on a patched version and consider restricting access to the plugin's functionality as a precaution.

Is there a patched version available?

No official fix has been published yet. You should monitor the sources for updates on a patched version.

Sources

Join the 0Day waitlist →

← Back to all threats