Description
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to change the password of arbitrary user accounts, including administrators, which can be leveraged to gain access to those accounts.
Published: 2026-08-07
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The TrueBooker plugin for WordPress allows an attacker to change any user’s password without authentication by omitting proper authorization checks. This flaw enables unauthenticated users to reset passwords for any account, including administrators, thereby compromising account integrity and potentially all system access. The weakness is a classic missing authorization bug, labeled with CWE‑862.

Affected Systems

The affected product is the TrueBooker – Appointment Booking and Scheduler System, a WordPress plugin sold by TheTechMount. All releases up to and including version 1.2.3 are vulnerable; no later versions are known to be affected.

Risk and Exploitability

The CVSS score of 9.8 places this vulnerability in the Critical category. Because EPSS data is unavailable, the exact likelihood of exploitation cannot be quantified. Based on the description, it is inferred that the absence of authentication checks permits an attacker to trigger a password reset by sending a crafted HTTP request containing the truebooker_wp_user_id parameter; this implies a high likelihood of exploitation if an attacker can reach the endpoint. Attacks are likely to come from external actors who can send such a request. The issue is not currently listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 7, 2026 at 07:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the TrueBooker plugin to the latest version that includes the authorization fix.
  • If upgrading is not immediately possible, configure the web application firewall or server to block unauthenticated POST/GET requests containing the truebooker_wp_user_id parameter.
  • Implement monitoring of password reset logs for anomalous activity and review user accounts for unauthorized changes.

Generated by OpenCVE AI on August 7, 2026 at 07:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Themetechmount
Themetechmount truebooker-appointment-booking
Wordpress
Wordpress wordpress
Vendors & Products Themetechmount
Themetechmount truebooker-appointment-booking
Wordpress
Wordpress wordpress

Fri, 07 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Description The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to change the password of arbitrary user accounts, including administrators, which can be leveraged to gain access to those accounts.
Title TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id'
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Themetechmount Truebooker-appointment-booking
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-07T17:37:09.939Z

Reserved: 2026-07-01T19:24:23.000Z

Link: CVE-2026-14365

cve-icon Vulnrichment

Updated: 2026-08-07T17:37:05.462Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T05:16:57.883

Modified: 2026-08-12T21:00:52.257

Link: CVE-2026-14365

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:00:05Z

Weaknesses