TrueBooker WordPress Plugin Vulnerable to Account Takeover: Early Warning
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress, in versions up to and including 1.2.3, appears to be vulnerable to account takeover due to improper password reset validation. This could allow unauthenticated attackers to reset passwords of arbitrary user accounts, including administrators.
What happened
An early warning has been issued regarding a critical vulnerability in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress. The vulnerability, tracked as CVE-2026-14364, reportedly affects all versions of the plugin up to and including 1.2.3. The issue stems from improper validation during the password reset process, which could enable unauthenticated attackers to reset the passwords of arbitrary user accounts, including those with administrative privileges.
The vulnerability has been assigned a CVSS score of 9.8, indicating a critical severity level. The National Vulnerability Database (NVD) has published the CVE record, but further details and validation are under investigation. Users of the TrueBooker plugin are advised to upgrade to the latest version as soon as it becomes available and to ensure that proper password reset validation mechanisms are in place.
For more detailed information, consult the primary sources, including the NVD entry for CVE-2026-14364. Given the severity of this vulnerability, it is crucial for system administrators and developers to stay updated on any patches or fixes released by the plugin's maintainers.
How 0Day mitigates this
truebooker-appointment-booking-and-scheduler-system is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.