CVE-2026-14349: TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action

Published Sep 16, 2026
·
Updated

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the email address of arbitrary user accounts, including administrators, which can be leveraged to reset the account's password and gain access to it.

Affected Software

1 affected component
WordPress plugin TrueBooker – Appointment Booking and Scheduler System<=1.2.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WordPress plugin: TrueBooker – Appointment Booking and Scheduler System to a version that resolves this vulnerability.

    Fixed in 1.2.3
  2. Compensating control

    Apply an access control compensating measure by restricting or blocking unauthenticated requests to the TrueBooker WordPress AJAX action 'admin_addcustomer' (e.g., deny/allow at a WAF/endpoint level) until the plugin is updated.

Event History

Sep 16, 2026
CVE Published
via MITRE·03:28 AM
Data Sourced
via MITRE·03:28 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

WordPress sites running the TrueBooker – Appointment Booking and Scheduler System plugin at version 1.2.3 or earlier are affected.

2

Does exploitation require an account or user interaction?

No. The vulnerability can be exploited by an unauthenticated attacker and does not require user interaction.

3

What access could an attacker gain?

An attacker can change the email address for arbitrary WordPress user accounts, including administrator accounts. They may then use password-reset functionality to take over the affected account.

4

What should be done to remediate the issue?

Update the plugin to a version newer than 1.2.3, as the referenced change identifies version 1.2.4 as containing an update to the affected AJAX handling.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203