External risk intelligence

TrueBooker WordPress Plugin Account Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-14364

This vulnerability affects a WordPress appointment booking plugin. WordPress sites and their associated booking/scheduling plugins are typically deployed as public-facing web applications to enable user interaction and appointment management from the internet.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security flaw has been identified in a WordPress plugin used for appointment booking. This vulnerability allows unauthorized individuals to take over user accounts, including those of administrators, by exploiting a weakness in the password reset process. The potential for unauthorized access to sensitive data and system control presents a significant risk.

  • Account takeover via password reset flaw.
  • Critical access risk to booking systems.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by targeting the password reset function of the TrueBooker plugin. By bypassing identity checks during the password reset process, an attacker can gain control of any user account, including administrator accounts, on a vulnerable WordPress site. This could lead to a complete account takeover.

  • No authentication needed to start.
  • Attacker resets any user password.
  • Risk of full account takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to take over any user account within the TrueBooker appointment booking system. When supported by the advisory, this could affect account credentials and any data accessible through those compromised accounts.

  • User account credentials.
  • Arbitrary password resets are possible.
  • Unauthorized account access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the TrueBooker WordPress plugin requires immediate attention from teams managing public-facing web applications and WordPress instances. The first practical step is to identify all instances of the TrueBooker plugin, confirm their exposure to the internet, and determine their business criticality. Subsequently, the accountable owner should be identified to plan for remediation, prioritizing affected systems based on risk and potential impact.

  • WordPress administrators and site owners.
  • Verify plugin installation and public exposure.
  • Plan coordinated plugin updates or disablement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TrueBooker plugin used for?

TrueBooker is a WordPress plugin designed to handle appointment scheduling and booking. It is typically installed on websites to allow customers to view availability and reserve time slots directly through the site interface.

What is the weakness class for CVE-2026-14364?

This vulnerability is classified as CWE-640, which refers to weak password recovery validation. In this case, the plugin fails to properly verify a user's identity during the password reset process, allowing an attacker to manipulate the recovery flow to change account credentials.

How can an attacker trigger this vulnerability?

An attacker triggers this by interacting with the plugin's password reset function without needing to log in first. It is important to note that this flaw does not require the attacker to know the current password or have access to the user's email; the plugin simply fails to perform the necessary identity checks to confirm the reset request is legitimate.

Why is this CVE considered relevant to my site?

According to Halo Surface Signal, this vulnerability is highly relevant because WordPress booking plugins are almost always deployed on public-facing websites to enable internet access. If your site uses this plugin, it is directly exposed to the internet, making it reachable by any remote attacker.

Do I need to take action if I use TrueBooker?

Yes. Start by identifying all instances of the TrueBooker plugin running within your WordPress environment. Once located, confirm if the site is internet-facing and determine the business impact of a potential account compromise, then coordinate with your team to update the plugin or disable it until a secure version is verified.

References