Junglewise Threat Intelligence

CVE-2026-14349: TrueBooker , Appointment Booking and Scheduler System authorization bypass

CVE-2026-14349 · Severity: critical · CVSS 9.8 · Published 2026-09-16

Executive brief

The TrueBooker WordPress plugin provides appointment booking and scheduling functionality for websites. An unauthenticated attacker can bypass authorization checks to modify any user's email address, including administrators, and then reset their password to gain full account access and control over the WordPress site.

Technical details

The plugin contains an authorization bypass vulnerability in its AJAX functions due to improper verification of user permissions before processing account modifications. An unauthenticated attacker can directly invoke the vulnerable endpoint to change email addresses on arbitrary user accounts. The vulnerability does not require authentication, user interaction, or elevated privileges. By changing an administrator's email address, an attacker can leverage WordPress's password reset mechanism to gain unauthorized access to privileged accounts and compromise the entire site. The vulnerability was fixed in version 1.2.4.

Affected products

  • TrueBooker TrueBooker – Appointment Booking and Scheduler System up to and including 1.2.3

Timeline

  • 2026-09-16: disclosed

References