Description
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
Published: 2026-08-19
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker can exploit a flaw in the TrueBooker WordPress plugin (version 1.2.6 and below) to elevate privileges on the affected site. The weakness allows unauthorized users to take control over the WordPress environment, potentially granting full administrative access and enabling modifications, data theft, or further attacks. This vulnerability is categorized as a high‑severity privilege escalation (CWE-266).

Affected Systems

WordPress sites that install ThemetechMount's TrueBooker plugin with versions 1.2.6 or older are vulnerable. The vulnerability exists in any instance of this plugin running on a WordPress installation without the patch.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical risk, and the EPSS score is < 1%, implying that current exploitation probability data is lacking but does not diminish the inherent severity. The vulnerability is not listed in CISA’s KEV catalog, though the lack of exploitation evidence does not negate the need for prompt remediation. It is inferred that the attack vector is via the plugin’s exposed administrative interfaces, which can be accessed without authentication, allowing an attacker to trigger the privilege escalation. The compromise would allow the attacker to generate new administrative credentials, exfiltrate data, and possibly pivot to additional assets.

Generated by OpenCVE AI on August 20, 2026 at 18:02 UTC.

Remediation

Vendor Solution

Update the WordPress TrueBooker Plugin to the latest available version (at least 1.2.7).


OpenCVE Recommended Actions

  • Update the TrueBooker plugin to version 1.2.7 or newer
  • If an update cannot be applied immediately, disable or uninstall the vulnerable plugin from the site
  • Limit access to the WordPress admin dashboard and plugin configuration pages to users with appropriate privileges only, and review existing user roles for unnecessary capabilities
  • Monitor site logs for unusual access patterns or repeated attempts to exploit the plugin’s administrative functions

Generated by OpenCVE AI on August 20, 2026 at 18:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Themetechmount
Themetechmount truebooker
Wordpress
Wordpress wordpress
Vendors & Products Themetechmount
Themetechmount truebooker
Wordpress
Wordpress wordpress

Wed, 19 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
Title WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Themetechmount Truebooker
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T15:57:13.300Z

Reserved: 2026-08-12T10:51:08.683Z

Link: CVE-2026-73347

cve-icon Vulnrichment

Updated: 2026-08-20T15:54:27.276Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T13:18:07.123

Modified: 2026-08-20T16:17:54.327

Link: CVE-2026-73347

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T18:15:04Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment