Description
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the email address of arbitrary user accounts, including administrators, which can be leveraged to reset the account's password and gain access to it.
Published: 2026-09-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of user email leading to possible account takeover
Action: Patch Immediately
AI Analysis

Impact

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress contains an authorization bypass that lets an unauthenticated user change the email address of any user account, including administrators. By altering an administrator’s email, the attacker can trigger a password reset and subsequently gain control of that account. This flaw is a classic example of authorization bypass (CWE-862) and directly threatens the integrity and control of the site’s administrative functions.

Affected Systems

All WordPress installations using the TrueBooker plugin version 1.2.3 or earlier are affected. Sites running those releases are vulnerable until they upgrade to 1.2.4 or later.

Risk and Exploitability

The CVSS score is 9.8, marking the flaw as critical. The EPSS score is less than 1%, indicating a very low probability of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated AJAX request to the vulnerable 'admin_addcustomer' endpoint; the request can be issued from any network and requires no credentials. Because the bypass allows modification of any user’s email address, a single unauthenticated request is sufficient to trigger a password reset and could lead to account takeover.

Generated by OpenCVE AI on September 18, 2026 at 12:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the TrueBooker plugin to version 1.2.4 or newer, which removes the broken authorization check.
  • If an upgrade cannot be performed immediately, block unauthenticated access to the 'admin_addcustomer' AJAX route using firewall rules or web‑server configuration to deny requests from users who are not logged in.
  • Review and restrict other AJAX endpoints to ensure no similar authorization gaps remain, and consider enabling two‑factor authentication for administrator accounts as additional protection.

Generated by OpenCVE AI on September 18, 2026 at 12:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Description The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the email address of arbitrary user accounts, including administrators, which can be leveraged to reset the account's password and gain access to it.
Title TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-16T18:57:03.584Z

Reserved: 2026-07-01T16:13:40.244Z

Link: CVE-2026-14349

cve-icon Vulnrichment

Updated: 2026-09-16T18:56:59.675Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T04:17:58.777

Modified: 2026-09-16T19:17:06.020

Link: CVE-2026-14349

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T13:00:11Z

Weaknesses