Impact
An unauthenticated attacker can exploit a flaw in the TrueBooker WordPress plugin (version 1.2.6 and below) to elevate privileges on the affected site. The weakness allows unauthorized users to take control over the WordPress environment, potentially granting full administrative access and enabling modifications, data theft, or further attacks. This vulnerability is categorized as a high‑severity privilege escalation (CWE-266).
Affected Systems
WordPress sites that install ThemetechMount's TrueBooker plugin with versions 1.2.6 or older are vulnerable. The vulnerability exists in any instance of this plugin running on a WordPress installation without the patch.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical risk, and the EPSS score is < 1%, implying that current exploitation probability data is lacking but does not diminish the inherent severity. The vulnerability is not listed in CISA’s KEV catalog, though the lack of exploitation evidence does not negate the need for prompt remediation. It is inferred that the attack vector is via the plugin’s exposed administrative interfaces, which can be accessed without authentication, allowing an attacker to trigger the privilege escalation. The compromise would allow the attacker to generate new administrative credentials, exfiltrate data, and possibly pivot to additional assets.
OpenCVE Enrichment