{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/truebooker--appointment-booking-and-scheduler-system--1.2.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-18315"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TrueBooker – Appointment Booking and Scheduler System (\u003c= 1.2.6)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe TrueBooker - Appointment Booking and Scheduler System plugin for WordPress contains a critical authorization bypass vulnerability (CVE-2026-18315) affecting all versions up to and including 1.2.6. The vulnerability resides within the 'admin_user_create_cus' AJAX handler, which fails to perform necessary authentication or capability checks.\u003c/p\u003e\n\u003cp\u003eAttackers can supply a 'truebooker_wp_user_id' parameter to the affected endpoint, which is then processed by 'wp_update_user' without verifying if the requestor has administrative privileges. By leveraging this, an unauthenticated actor can overwrite the email address associated with any user account in the WordPress database, including administrative accounts. Once the email address is updated to one controlled by the attacker, they can initiate the standard WordPress password reset process, intercept the recovery link, and gain full control over the compromised account. Defenders should identify any WordPress installations running this plugin and update to a patched version or disable the functionality immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in a total account takeover for any user, including site administrators. Successful exploitation leads to full unauthorized access to the WordPress environment, enabling the attacker to modify site content, inject malicious scripts, redirect traffic, or exfiltrate sensitive data. Given that this plugin is used for scheduling, the compromise could also lead to the exposure of customer personal information and booking logs. There are no observed victim counts at this time, but the exploit is trivial to execute remotely.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the TrueBooker plugin to the latest version immediately to remediate the vulnerable AJAX handler.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user accounts for suspicious email address changes or recently created administrator accounts.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to detect attempts to reach the vulnerable AJAX handler from external sources.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP POST requests to 'admin-ajax.php' containing the 'admin_user_create_cus' action.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-19T20:38:23Z","date_published":"2026-08-19T20:38:23Z","id":"https://feed.craftedsignal.io/briefs/2026-08-truebooker-auth-bypass/","summary":"The TrueBooker plugin for WordPress up to version 1.2.6 is vulnerable to an unauthenticated account takeover via a flawed AJAX handler that allows attackers to modify user email addresses.","title":"Unauthenticated Account Takeover in TrueBooker WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-truebooker-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - TrueBooker – Appointment Booking and Scheduler System (\u003c= 1.2.6)","version":"https://jsonfeed.org/version/1.1"}