{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3atruebooker_projecttruebookerwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:truebooker_project:truebooker:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-14349"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TrueBooker – Appointment Booking and Scheduler System (\u003c= 1.2.3)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","vulnerability","authorization-bypass"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe TrueBooker - Appointment Booking and Scheduler System plugin for WordPress is vulnerable to an authorization bypass flaw (CVE-2026-14349) affecting all versions up to and including 1.2.3. The vulnerability stems from a failure to perform adequate authorization checks on critical administrative functions. An unauthenticated attacker can exploit this flaw to update the email address associated with any user account, including those with administrator privileges. By redirecting the administrative email address to an attacker-controlled account, the adversary can initiate a standard WordPress password reset request. This mechanism allows the attacker to hijack administrative sessions, potentially leading to full site compromise, data exfiltration, and the deployment of persistent backdoors within the WordPress environment. This vulnerability is highly severe given its ease of exploitation and the direct path to privilege escalation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain full administrative control over the affected WordPress installation. This can result in complete site compromise, unauthorized access to sensitive booking data, customer information exfiltration, and the installation of malicious software or redirect scripts. The vulnerability impacts any organization relying on the TrueBooker plugin for scheduling, regardless of their specific industry.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIdentify all WordPress installations utilizing the TrueBooker plugin.\u003c/li\u003e\n\u003cli\u003eImmediate remediation: Update the TrueBooker - Appointment Booking and Scheduler System plugin to the latest version as soon as a patch is released by the developer.\u003c/li\u003e\n\u003cli\u003eIf a patch is unavailable, deactivate or remove the plugin until a secure version is confirmed.\u003c/li\u003e\n\u003cli\u003eConduct an audit of administrative user accounts for unauthorized email changes or suspicious activity log entries.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to restrict access to administrative API endpoints associated with user profile modification.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-16T05:46:26Z","date_published":"2026-09-16T05:46:26Z","id":"https://feed.craftedsignal.io/briefs/2026-09-truebooker-auth-bypass/","summary":"The TrueBooker Appointment Booking and Scheduler System plugin for WordPress contains an authorization bypass vulnerability allowing unauthenticated attackers to modify arbitrary user email addresses and facilitate account takeover.","title":"Authorization Bypass in TrueBooker WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-truebooker-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:truebooker_project:truebooker:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}