Skip to content
Threat Feed
critical advisory

Authorization Bypass in TrueBooker WordPress Plugin

The TrueBooker Appointment Booking and Scheduler System plugin for WordPress contains an authorization bypass vulnerability allowing unauthenticated attackers to modify arbitrary user email addresses and facilitate account takeover.

CVE search metadata

CVE search record: CVE-2026-14349. Severity: critical. CVSS: 9.8. KEV: no. Product: TrueBooker – Appointment Booking and Scheduler System (<= 1.2.3). Brief: Authorization Bypass in TrueBooker WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-09-truebooker-auth-bypass/

The TrueBooker - Appointment Booking and Scheduler System plugin for WordPress is vulnerable to an authorization bypass flaw (CVE-2026-14349) affecting all versions up to and including 1.2.3. The vulnerability stems from a failure to perform adequate authorization checks on critical administrative functions. An unauthenticated attacker can exploit this flaw to update the email address associated with any user account, including those with administrator privileges. By redirecting the administrative email address to an attacker-controlled account, the adversary can initiate a standard WordPress password reset request. This mechanism allows the attacker to hijack administrative sessions, potentially leading to full site compromise, data exfiltration, and the deployment of persistent backdoors within the WordPress environment. This vulnerability is highly severe given its ease of exploitation and the direct path to privilege escalation.

Impact

Successful exploitation allows unauthenticated attackers to gain full administrative control over the affected WordPress installation. This can result in complete site compromise, unauthorized access to sensitive booking data, customer information exfiltration, and the installation of malicious software or redirect scripts. The vulnerability impacts any organization relying on the TrueBooker plugin for scheduling, regardless of their specific industry.

Recommendation

  1. Identify all WordPress installations utilizing the TrueBooker plugin.
  2. Immediate remediation: Update the TrueBooker - Appointment Booking and Scheduler System plugin to the latest version as soon as a patch is released by the developer.
  3. If a patch is unavailable, deactivate or remove the plugin until a secure version is confirmed.
  4. Conduct an audit of administrative user accounts for unauthorized email changes or suspicious activity log entries.
  5. Implement web application firewall (WAF) rules to restrict access to administrative API endpoints associated with user profile modification.

Immediate actions

Inventory and patch all WordPress sites running TrueBooker plugin

IT Operations 24h

Mitigations

Remove or disable plugin until a vendor-supplied patch is installed

immediate IT Operations

CVE-2026-14349