CVE-2026-14349
2· 1 readUnauthenticated Authorization Bypass in WordPress TrueBooker Booking Plugin
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress contains an authorization bypass (CWE-862, missing authorization check) in all versions up to and including 1.2.3. Because the plugin does not properly verify that a user is authorized to perform an action, an unauthenticated attacker can craft a request to change the email address of arbitrary user accounts, including administrators. Once the email address is changed, the attacker can trigger a password reset and take over the account, ultimately gaining full administrative access to the affected site. Any WordPress site running TrueBooker at or below version 1.2.3 is affected; the flaw is rated critical (CVSS 3.1: 9.8). No public proof-of-concept or exploitation in the wild is currently known.
What to do: Update TrueBooker to the latest available version immediately, since every release through 1.2.3 is vulnerable; if no fixed version is available yet, deactivate and remove the plugin. Audit user accounts — especially administrators — for unexpected email address changes or password resets that could indicate compromise. Enable two-factor authentication on administrator accounts and rotate passwords for any account showing signs of tampering.
| TrueBooker – Appointment Booking and Scheduler System (WordPress plugin) | All versions up to and including 1.2.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the email address of arbitrary user accounts, including administrators, which can be leveraged to reset the account's password and gain access to it.
- Ecosystems
- WordPress
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.