Authorization Bypass in TrueBooker Appointment Booking Plugin for WordPress
CVE-2026-14349
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-14349?
The TrueBooker Appointment Booking and Scheduler System plugin for WordPress contains a security flaw that allows unauthorized users to bypass authorization checks. This issue impacts all versions up to and including 1.2.3, enabling attackers to modify the email addresses of any user account, including those of administrators. By exploiting this vulnerability, an attacker can reset passwords and gain unauthorized access, posing significant security risks to WordPress websites utilizing this plugin.
Affected Version(s)
TrueBooker β Appointment Booking and Scheduler System 0 <= 1.2.3