CVE-2026-14545: TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password Reset
The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14545?
CVE-2026-14545 has a CVSS score of 93, indicating a critical risk level.
How do I fix CVE-2026-14545?
To fix CVE-2026-14545, update the TrueBooker Appointment Booking plugin to version 1.2.4 or higher.
What can an attacker do with CVE-2026-14545?
An attacker can take over any user's account, including administrator accounts, by resetting the password without authentication.
What versions are affected by CVE-2026-14545?
CVE-2026-14545 affects all versions of TrueBooker Appointment Booking prior to 1.2.4.
Is user action required to exploit CVE-2026-14545?
No user action is required; attackers can exploit CVE-2026-14545 without having to authenticate.