PT-2026-65390 · WordPress · Truebooker

·

CVE-2026-14545

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TrueBooker versions prior to 1.2.4
Description An issue exists in the TrueBooker WordPress plugin where account ownership is not validated during the password reset process via a front-end account handler. This allows unauthenticated attackers to set an arbitrary password for any account, including those with administrator privileges, leading to full site takeover.
Recommendations Update TrueBooker to version 1.2.4 or later.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14545

Affected Products

Truebooker