A security flaw has been found in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress. The issue impacts all versions of the plugin up to and including version 1.2.3, and stems from the plugin failing to properly verify a person’s identity before processing a password reset request.
This vulnerability allows unauthenticated attackers, meaning people who do not have any existing account on your site, to reset the password for any user on your site, including site administrators. If exploited, this could let an attacker take full control of the affected user account, gain access to your website’s backend, view sensitive data, or make unauthorized changes to your site’s content and settings.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14364