๐Ÿ” CVE Alert

CVE-2026-14545

UNKNOWN 0.0

TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password Reset

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.

Vendor unknown
Product truebooker
Published Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for unknown truebooker

Be the first to know when new unknown vulnerabilities affecting unknown truebooker are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / TrueBooker
0 < 1.2.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c97d9841-2bd7-438b-a719-7943d671c754/

Credits

Pedro Pinho WPScan