CVE-2026-14365 (matched: wordpress)

  • Friday, 7th August, 2026
  • 16:05pm

A security flaw has been found in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress, a tool used to manage appointment bookings on websites. The issue impacts every version of the plugin up to and including version 1.2.3, and occurs because the plugin does not properly check if a person trying to make changes is allowed to do so.

This gap means that people who do not have a login for your website can change the passwords for any user account on the site, including administrator accounts. If an attacker gains access to an administrator account, they can take full control of your website and its content.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14365

« Back