CVE-2026-14545
TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password Reset
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.
| Vendor | unknown |
| Product | truebooker |
| Published | Jul 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown truebooker
Be the first to know when new unknown vulnerabilities affecting unknown truebooker are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / TrueBooker
0 < 1.2.4
References
Credits
Pedro Pinho WPScan