CVE-2026-14364
themetechmount · TrueBooker – Appointment Booking and Scheduler System
The TrueBooker WordPress plugin is vulnerable to account takeover due to improper password reset validation, allowing unauthenticated attackers to reset passwords for arbitrary user accounts.
Executive summary
A critical vulnerability in the TrueBooker plugin allows unauthenticated attackers to perform account takeovers, potentially granting them full administrative control over the affected WordPress site.
Vulnerability
The plugin contains a weak password recovery mechanism (CWE-640) that fails to properly validate a user's identity during the reset process. This flaw allows unauthenticated remote attackers to trigger password resets for any account, including administrative users.
Business impact
With a CVSS score of 9.8, this vulnerability represents an existential threat to the integrity of the WordPress environment. An attacker gaining administrative access can compromise all stored data, inject malicious content, or use the server as a vector for further attacks, leading to significant reputational and operational damage.
Remediation
Immediate Action: Update the TrueBooker – Appointment Booking and Scheduler System plugin to version 1.2.4 or higher immediately.
Proactive Monitoring: Review WordPress user logs for unexpected password reset activity or unauthorized administrative account modifications.
Compensating Controls: If the update cannot be applied immediately, deactivate the plugin to prevent exploitation of the insecure password recovery function.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this flaw necessitates immediate remediation. Administrators should ensure the plugin is updated to 1.2.4 and perform an audit of all user accounts for suspicious activity or unauthorized password changes that may have occurred prior to patching.