CVE-2026-61951
themetechmount · TrueBooker
TrueBooker for WordPress is vulnerable to an unauthenticated privilege escalation, allowing unauthorized users to gain elevated access.
Executive summary
The TrueBooker plugin for WordPress contains a critical privilege escalation vulnerability that allows unauthenticated attackers to gain administrative control over the affected site.
Vulnerability
This is an incorrect privilege assignment vulnerability (CWE-266) that permits an unauthenticated attacker to manipulate plugin functions to escalate their account permissions.
Business impact
The vulnerability carries a CVSS score of 9.8, reflecting its critical nature. A successful exploit could lead to a full site takeover, unauthorized data access, and the potential for persistent backdoors to be installed by the attacker, resulting in significant reputational and operational damage.
Remediation
Immediate Action: Update the TrueBooker plugin to version 1.2.4 or later immediately.
Proactive Monitoring: Review WordPress user account logs for unexpected administrative role changes or newly created administrator accounts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests directed at plugin-specific API endpoints until the update is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical severity and the ease of exploitation (unauthenticated), administrators must prioritize patching this plugin immediately. Failure to update to version 1.2.4 leaves the entire WordPress environment susceptible to compromise.