VYPR
Critical severity9.1NVD Advisory· Published Jun 15, 2026· Updated Jun 15, 2026

CVE-2026-48881

CVE-2026-48881

Description

Unauthenticated broken access control in TrueBooker <=1.1.9 allows attackers to perform privileged actions without authentication, leading to critical site compromise.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated broken access control in TrueBooker <=1.1.9 allows attackers to perform privileged actions without authentication, leading to critical site compromise.

Vulnerability

A broken access control vulnerability exists in the TrueBooker plugin for WordPress versions 1.1.9 and earlier, as disclosed in Patchstack advisory [1]. The flaw allows unauthenticated users to access functions that should require proper authorization or nonce checks, enabling unauthorized privileged actions. All installations running version 1.1.9 or below are affected.

Exploitation

An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests to the vulnerable endpoints without needing any prior access, user interaction, or special network position. The lack of authentication or nonce validation means the attack can be performed remotely and automatically, making it suitable for mass-exploit campaigns [1].

Impact

Successful exploitation grants the attacker the ability to execute higher-privileged actions, such as modifying or deleting data, bypassing restrictions, or performing unauthorized operations within the WordPress installation. Given the unauthenticated nature and critical severity (CVSS 9.1), the impact can lead to full site compromise [1].

Mitigation

Immediately update to version 1.2.0 or later, which contains the fix. Patchstack also provides a mitigation rule to block attacks until the update is applied. No other workarounds have been disclosed [1].

AI Insight generated on Jun 15, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

1