A security vulnerability has been identified in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress. All versions of this plugin up to and including 1.2.3 are affected by this issue. The flaw occurs because the plugin does not properly confirm a user's identity when handling password reset requests. This allows unauthenticated attackers (people who do not have a valid account on your site) to reset the password for any user account on your site, including administrator accounts, and gain full control of those accounts. If you use this plugin to manage appointments or scheduling on your WordPress site, a successful attack could let an intruder change your site's content, access sensitive customer information stored in your booking system (such as contact details and appointment records), or add harmful software to your site.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14364