Product
The TrueBooker plugin for WordPress up to version 1.2.6 is vulnerable to an unauthenticated account takeover via a flawed AJAX handler that allows attackers to modify user email addresses.