TrueBooker WordPress Plugin Vulnerable to Account Takeover
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- truebooker plugin (wordpress)
- Patched version
- Not yet available
An early warning has been issued for a critical vulnerability in the TrueBooker WordPress plugin. Versions up to and including 1.2.6 are reportedly affected.
What happened
The TrueBooker plugin for WordPress is under investigation for a critical vulnerability that could lead to account takeover. This is due to the add_front_user_update() AJAX handler being accessible to unauthenticated users and accepting an arbitrary truebooker_wp_user_id value, which is passed directly to wp_update_user() without verifying authentication or ownership. The vulnerability has been assigned the identifier CVE-2026-16142 with a CVSS score of 9.8, indicating a critical severity level.
There is no evidence at this time that the vulnerability has been exploited in the wild. However, given the severity and potential impact, it is crucial for users of the TrueBooker plugin to assess their exposure and take appropriate action.
What to do about it
- Review your WordPress installation to determine if the TrueBooker plugin is in use and if it is version 1.2.6 or earlier.
- If you are using an affected version, monitor the official sources for updates on a patched version.
- As a precautionary measure, consider restricting access to the TrueBooker plugin's functionality until a patch is available.
- Stay informed by following updates from the National Vulnerability Database and other reputable sources.
- No official fix has been published yet. Monitor the sources below for updates on a patched version.
How 0Day would have caught this
truebooker plugin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using the TrueBooker plugin for WordPress and your version is 1.2.6 or earlier, you are reportedly affected.
What should I do right now?
Review your WordPress installation to determine if you are using an affected version of the TrueBooker plugin. Monitor official sources for updates on a patched version and consider restricting access to the plugin's functionality as a precaution.
Is there a patched version available?
No official fix has been published yet. You should monitor the sources for updates on a patched version.