


Perceptive Security
SOC/SIEM Consultancy

The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers…
Published:
27 juli 2026 om 22:00:00
Alert date:
28 juli 2026 om 15:00:57
Source:
nvd.nist.gov
Web Technologies, Identity & Access
A critical authentication bypass vulnerability exists in the TrueBooker WordPress plugin before version 1.2.4. The plugin fails to validate account ownership during the password reset process through its front-end account handler. This flaw allows unauthenticated attackers to set an arbitrary password on any user account, including administrator accounts. Successful exploitation enables full site takeover without any prior authentication. The vulnerability is tracked as CVE-2026-14545 and has been patched in version 1.2.4 of the plugin.
Technical details
Mitigation steps:
Affected products:
TrueBooker WordPress Plugin < 1.2.4
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-14545
https://wpscan.com/vulnerability/c97d9841-2bd7-438b-a719-7943d671c754/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
