Impact
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress contains an authorization bypass that lets an unauthenticated user change the email address of any user account, including administrators. By altering an administrator’s email, the attacker can trigger a password reset and subsequently gain control of that account. This flaw is a classic example of authorization bypass (CWE-862) and directly threatens the integrity and control of the site’s administrative functions.
Affected Systems
All WordPress installations using the TrueBooker plugin version 1.2.3 or earlier are affected. Sites running those releases are vulnerable until they upgrade to 1.2.4 or later.
Risk and Exploitability
The CVSS score is 9.8, marking the flaw as critical. The EPSS score is less than 1%, indicating a very low probability of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated AJAX request to the vulnerable 'admin_addcustomer' endpoint; the request can be issued from any network and requires no credentials. Because the bypass allows modification of any user’s email address, a single unauthenticated request is sufficient to trigger a password reset and could lead to account takeover.
OpenCVE Enrichment