TrueBooker WordPress Plugin Vulnerable to Authorization Bypass
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress appears to be vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This reportedly allows unauthenticated attackers to change user account passwords, including administrators.
What happened
An early warning has been issued regarding a critical vulnerability in the TrueBooker plugin for WordPress. The plugin, in all versions up to and including 1.2.3, is under investigation for an authorization bypass issue. This vulnerability reportedly allows unauthenticated attackers to change the passwords of arbitrary user accounts, including those with administrative privileges.
The vulnerability, tracked as CVE-2026-14365 with a CVSS score of 9.8, is due to the plugin not properly verifying user authorization before performing actions. This can be exploited to gain unauthorized access to user accounts.
Professional software engineers using the TrueBooker plugin are advised to upgrade to a version beyond 1.2.3 as soon as it becomes available. Additionally, it is recommended to review user accounts for any unauthorized changes. For the most accurate and up-to-date information, consult the primary sources linked in the summary.
How 0Day mitigates this
truebooker plugin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.