Unauthenticated Privilege Escalation in TrueBooker Plugin by Patchstack
CVE-2026-61951
9.8CRITICAL
What is CVE-2026-61951?
The TrueBooker plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to 1.2.3. This vulnerability allows attackers to gain unauthorized access and potentially exploit the system, leading to elevated permissions without the need for valid authentication. Users are strongly encouraged to update to the latest version to mitigate this risk.
Affected Version(s)
TrueBooker <= 1.2.3