A security flaw tracked as CVE-2026-14365 has been found in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress, a tool many service website owners use to let customers book appointments directly on their sites. All versions of this plugin up to and including version 1.2.3 are affected by this issue.
The problem is an authorization bypass: the plugin does not properly verify that a person is allowed to make changes to user accounts. This makes it possible for anyone who visits your website, even if they are not logged in or have no approved access to your site, to change the passwords for any user accounts on your site, including administrator accounts.
If an attacker gains access to an admin account, they can take full control of your website. This could let them alter your site’s content, access private customer or business data, or use your site to spread harmful content to your visitors.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14365