CVE-2026-14365 CRITICAL

CVE-2026-14365: TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id'

Vendor Themetechmount
Product TrueBooker – Appointment Booking and Scheduler System
Weakness CWE-862 · Missing authorization
Published August 7, 2026
Last update August 7, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to change the password of arbitrary user accounts, including administrators, which can be leveraged to gain access to those accounts.

Explanation of Vulnerability in Simple Terms

02Summary

TrueBooker versions 1.2.3 and earlier lack authorization checks on core functionality. An unauthenticated attacker can read, modify, or delete appointment data and system settings without any credentials. This affects all installations and requires only network access to exploit.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete all appointment bookings and system configuration without logging in.

Potential impact on your site

04Site Impact

Complete compromise of appointment data and system integrity; attackers can cancel bookings, steal customer information, or disable the booking system.

Conditions required to exploit

05Prerequisites

Network access to the TrueBooker installation; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 7, 2026 CVE published
August 7, 2026 Record updated

Related vulnerabilities

08Related CVE