Impact
TrueBooker – Appointment Booking and Scheduler System for WordPress allows anyone who knows a user’s ID to trigger a password reset through the 'tbab-userid' parameter without any authentication. The plugin fails to verify that the requester actually owns the account, so an attacker can reset the credentials of any user, including administrators. This flaw represents a severe authorization bypass, identified as CWE‑640, and gives an attacker complete control over compromised accounts.
Affected Systems
The vulnerability affects the TrueBooker plugin from themetechmount, in all versions up to and including 1.2.3. Any WordPress site installing this plugin at the vulnerable version is at risk.
Risk and Exploitability
With a CVSS score of 9.8 the flaw is considered critical. While the EPSS score is currently unavailable, the lack of authentication requirement makes exploitation trivial under normal web attack conditions. The issue is not listed in CISA’s KEV catalog, but its potential for rapid breaking into administrator accounts makes it a high priority risk.
OpenCVE Enrichment