CVE-2026-61951

themetechmount · TrueBooker

TrueBooker for WordPress is vulnerable to an unauthenticated privilege escalation, allowing unauthorized users to gain elevated access.

Executive summary

The TrueBooker plugin for WordPress contains a critical privilege escalation vulnerability that allows unauthenticated attackers to gain administrative control over the affected site.

Vulnerability

This is an incorrect privilege assignment vulnerability (CWE-266) that permits an unauthenticated attacker to manipulate plugin functions to escalate their account permissions.

Business impact

The vulnerability carries a CVSS score of 9.8, reflecting its critical nature. A successful exploit could lead to a full site takeover, unauthorized data access, and the potential for persistent backdoors to be installed by the attacker, resulting in significant reputational and operational damage.

Remediation

Immediate Action: Update the TrueBooker plugin to version 1.2.4 or later immediately.

Proactive Monitoring: Review WordPress user account logs for unexpected administrative role changes or newly created administrator accounts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests directed at plugin-specific API endpoints until the update is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical severity and the ease of exploitation (unauthenticated), administrators must prioritize patching this plugin immediately. Failure to update to version 1.2.4 leaves the entire WordPress environment susceptible to compromise.