PT-2026-65390 · WordPress · Truebooker
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TrueBooker versions prior to 1.2.4
Description
An issue exists in the TrueBooker WordPress plugin where account ownership is not validated during the password reset process via a front-end account handler. This allows unauthenticated attackers to set an arbitrary password for any account, including those with administrator privileges, leading to full site takeover.
Recommendations
Update TrueBooker to version 1.2.4 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Truebooker