The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their account via the password reset flow.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-18776 affects the TrueBooker WordPress plugin versions before 1.2.7, exposing a critical authorization bypass vulnerability in AJAX actions. The plugin fails to properly validate user permissions before processing certain AJAX requests, allowing completely unauthenticated attackers to modify email addresses for any user account—including administrators. By changing an administrator's email address, attackers can leverage the password reset flow to gain complete account takeover. This vulnerability is particularly dangerous because it requires no user interaction, no authentication, and affects WordPress installations that depend on this plugin, potentially impacting thousands of websites managing bookings and user accounts.
While this specific CVE currently has 0 matching Casky skills, practitioners using Casky's Claude AI-powered platform would detect the underlying attack patterns through behavioral analysis of AJAX request anomalies and privilege escalation attempts mapped to MITRE ATT&CK. The attack chain—unauthenticated access to account modification (T1078: Valid Accounts), unauthorized privilege changes, and credential reset abuse—represents a classic authorization flaw pattern. Extended reasoning across Casky's 754 security skills would flag suspicious AJAX calls lacking proper authentication tokens, mass account modification requests from single sources, and rapid email-to-password reset sequences that deviate from normal user behavior, enabling defenders to identify exploitation attempts even before signature-based detection catches them.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-18776. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation