PT-2026-68852 · WordPress · Truebooker

·

CVE-2026-14364

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TrueBooker – Appointment Booking and Scheduler System versions prior to 1.2.4
Description This issue allows unauthenticated attackers to perform an account takeover by exploiting improper password reset validation. The plugin fails to properly verify a user's identity during the password reset process, enabling attackers to reset passwords for arbitrary accounts, including those with administrator privileges.
Recommendations Update TrueBooker – Appointment Booking and Scheduler System to version 1.2.4 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14364

Affected Products

Truebooker