top of page
perceptive_background_267k.jpg

The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers…

Published:

27 juli 2026 om 22:00:00

Alert date:

28 juli 2026 om 15:00:57

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

A critical authentication bypass vulnerability exists in the TrueBooker WordPress plugin before version 1.2.4. The plugin fails to validate account ownership during the password reset process through its front-end account handler. This flaw allows unauthenticated attackers to set an arbitrary password on any user account, including administrator accounts. Successful exploitation enables full site takeover without any prior authentication. The vulnerability is tracked as CVE-2026-14545 and has been patched in version 1.2.4 of the plugin.

Technical details

Mitigation steps:

Affected products:

TrueBooker WordPress Plugin < 1.2.4

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page