Improper Password Reset Validation in TrueBooker Appointment Booking System by WordPress
CVE-2026-14364

9.8CRITICAL

What is CVE-2026-14364?

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress contains a security flaw that enables unauthorized account access. This vulnerability arises from inadequate validation of a user's identity during the password reset process. As a result, attackers without authentication can exploit this weakness to reset passwords for any user account, including those of administrators, potentially leading to unauthorized access and control over the affected accounts.

Affected Version(s)

TrueBooker – Appointment Booking and Scheduler System 0 <= 1.2.3

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

thevietronin
.