PT-2026-68852 · WordPress · Truebooker
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TrueBooker – Appointment Booking and Scheduler System versions prior to 1.2.4
Description
This issue allows unauthenticated attackers to perform an account takeover by exploiting improper password reset validation. The plugin fails to properly verify a user's identity during the password reset process, enabling attackers to reset passwords for arbitrary accounts, including those with administrator privileges.
Recommendations
Update TrueBooker – Appointment Booking and Scheduler System to version 1.2.4 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Truebooker