ZeroHour

CVE-2026-14349

2· 1 read

Unauthenticated Authorization Bypass in WordPress TrueBooker Booking Plugin

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress contains an authorization bypass (CWE-862, missing authorization check) in all versions up to and including 1.2.3. Because the plugin does not properly verify that a user is authorized to perform an action, an unauthenticated attacker can craft a request to change the email address of arbitrary user accounts, including administrators. Once the email address is changed, the attacker can trigger a password reset and take over the account, ultimately gaining full administrative access to the affected site. Any WordPress site running TrueBooker at or below version 1.2.3 is affected; the flaw is rated critical (CVSS 3.1: 9.8). No public proof-of-concept or exploitation in the wild is currently known.

What to do: Update TrueBooker to the latest available version immediately, since every release through 1.2.3 is vulnerable; if no fixed version is available yet, deactivate and remove the plugin. Audit user accounts — especially administrators — for unexpected email address changes or password resets that could indicate compromise. Enable two-factor authentication on administrator accounts and rotate passwords for any account showing signs of tampering.

Affected
TrueBooker – Appointment Booking and Scheduler System (WordPress plugin)All versions up to and including 1.2.3
Estimated exposure
unknown — no public active-install or scan data available — The provided data includes no plugin active-install counts or internet-exposed deployment figures, and no basis was available to size the affected footprint.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the email address of arbitrary user accounts, including administrators, which can be leveraged to reset the account's password and gain access to it.

Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.