{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/truebooker--1.2.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-16142"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TrueBooker (\u003c= 1.2.6)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe TrueBooker plugin for WordPress (versions 1.2.6 and earlier) is susceptible to an unauthenticated account takeover vulnerability, designated as CVE-2026-16142. The flaw exists within the 'add_front_user_update()' AJAX handler, which fails to verify the authentication status or the ownership of the account being modified. Because the handler trusts user-supplied input for the 'truebooker_wp_user_id' parameter and passes it directly to the 'wp_update_user()' function, unauthenticated attackers can overwrite the email address associated with any user account, including administrative accounts. By redirecting a target account's email to an attacker-controlled address, the threat actor can leverage the native WordPress password reset functionality to seize control of the account. This vulnerability poses a severe risk to WordPress installations utilizing this plugin.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress installation running the vulnerable TrueBooker plugin version 1.2.6 or earlier.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious AJAX request targeting the 'add_front_user_update()' action.\u003c/li\u003e\n\u003cli\u003eAttacker specifies the 'truebooker_wp_user_id' parameter corresponding to the target administrator account ID.\u003c/li\u003e\n\u003cli\u003eAttacker provides an arbitrary, attacker-controlled email address in the request parameters.\u003c/li\u003e\n\u003cli\u003eThe vulnerable plugin accepts the request without authentication checks and executes 'wp_update_user()' using the provided inputs.\u003c/li\u003e\n\u003cli\u003eThe target administrator's email address is successfully updated in the WordPress database to the attacker's email address.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a standard password reset request for the target account via the legitimate WordPress '/wp-login.php?action=lostpassword' endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker intercepts the reset token delivered to their controlled email and completes the password reset, successfully achieving full account takeover.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain full administrative control over the affected WordPress site. This leads to complete data exfiltration, defacement, the potential for further server-side command execution via administrative privileges, and the compromise of all user data stored within the application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the update of the TrueBooker plugin to the latest patched version. If updates are unavailable, disable the plugin immediately. Monitor web server logs for suspicious POST requests to 'admin-ajax.php' containing the 'truebooker_wp_user_id' parameter.\u003c/p\u003e\n","date_modified":"2026-08-15T10:17:59Z","date_published":"2026-08-15T10:17:59Z","id":"https://feed.craftedsignal.io/briefs/2026-08-truebooker-ato/","summary":"The TrueBooker WordPress plugin contains an unauthenticated account takeover vulnerability (CVE-2026-16142) allowing attackers to modify arbitrary user email addresses and facilitate account hijacking.","title":"Account Takeover in TrueBooker WordPress Plugin via Unauthenticated AJAX","url":"https://feed.craftedsignal.io/briefs/2026-08-truebooker-ato/"}],"language":"en","title":"CraftedSignal Threat Feed - TrueBooker (\u003c= 1.2.6)","version":"https://jsonfeed.org/version/1.1"}