External risk intelligence

TrueBooker WordPress Plugin Authorization Bypass Allows Arbitrary Password Changes

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-14365

The vulnerability exists in a WordPress appointment booking plugin. Such plugins are designed to be public-facing components of a website, enabling end-users to interact with the system via the internet as part of their standard functional deployment.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security flaw has been identified in the TrueBooker Appointment Booking and Scheduler System for WordPress, allowing unauthenticated attackers to bypass authorization. This vulnerability could enable unauthorized individuals to reset passwords for any user account, including administrative ones, potentially leading to account compromise. The main concern is confirming the relevance and exposure of this plugin within your organization.

  • Unauthorized password resets are possible.
  • Admins can be locked out by attackers.
  • Confirm plugin use and exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending a specially crafted request to a vulnerable WordPress site. This request targets the TrueBooker plugin, bypassing authorization checks to alter user credentials. Successful exploitation allows an attacker to change the password of any user, including administrators, thereby taking over their accounts.

  • No authentication needed to attack.
  • Triggered by unauthorized actions in the plugin.
  • Risk of full account takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to bypass authorization checks within the TrueBooker plugin, potentially leading to unauthorized password changes for any user account, including administrators. This could result in a complete compromise of user accounts and the underlying WordPress site.

  • User account credentials.
  • Password resets via unauthorized requests.
  • Complete account takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the TrueBooker Appointment Booking and Scheduler System affects WordPress sites. The primary responsibility for addressing this lies with the application owners or the platform team managing the WordPress instances, as they control the plugins and their configurations. The initial practical step is to identify all WordPress sites utilizing this plugin, determine their reachability and business criticality, and then assign ownership for remediation planning and execution.

  • Application owners should own the issue.
  • Verify plugin usage and exposure.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TrueBooker plugin for WordPress?

TrueBooker is an appointment booking and scheduler system designed for WordPress websites. It allows site owners to manage calendars and accept customer bookings directly through their web interface, serving as a functional tool for service-based businesses to interact with their clients online.

What does CWE-862 mean for CVE-2026-14365?

CWE-862 refers to a missing authorization weakness. In the context of CVE-2026-14365, it means the TrueBooker plugin fails to check if a person has permission before executing an action. Because these security checks are absent, the system incorrectly trusts incoming requests, allowing unauthorized users to perform sensitive tasks like modifying account credentials.

How can an attacker trigger this vulnerability?

An attacker exploits this by sending a specially crafted request to the WordPress site that targets the TrueBooker plugin. Crucially, the attacker does not need to be logged in or have any prior account access to initiate this. The vulnerability is not triggered by standard site navigation but specifically by these unauthorized requests designed to bypass the plugin's internal permission logic.

Why is this CVE considered internet-facing?

According to Halo Surface Signal, this plugin is designed to be a public-facing component of a website. Because it must be reachable by end-users via the internet to function as a booking system, any site running this plugin presents a clear path for external interaction, increasing the importance of addressing the flaw.

What steps should I take if I use TrueBooker?

First, locate all WordPress instances in your environment that have the TrueBooker plugin installed. Once you have an inventory, assess the business criticality of those sites. Prioritize the update or removal of the plugin on public-facing sites to eliminate the authorization bypass risk and prevent potential account takeovers.

References