


Perceptive Security
SOC/SIEM Consultancy

The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers…
Published:
28 juli 2026 om 00:00:00
Alert date:
28 juli 2026 om 19:04:58
Source:
nvd.nist.gov
Web Technologies, Identity & Access
The TrueBooker WordPress plugin before version 1.2.4 contains a critical authentication bypass vulnerability in its front-end account handler. The plugin fails to validate account ownership during password reset operations, allowing unauthenticated attackers to set arbitrary passwords on any account. This includes administrator accounts, effectively enabling full site takeover. No authentication or prior privileges are required to exploit this vulnerability. The issue is resolved in version 1.2.4 of the plugin.
Technical details
Mitigation steps:
Affected products:
TrueBooker WordPress Plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-14545
https://wpscan.com/vulnerability/c97d9841-2bd7-438b-a719-7943d671c754/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
