<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:truebooker_project:truebooker:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3atruebooker_projecttruebookerwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 05:46:26 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3atruebooker_projecttruebookerwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in TrueBooker WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-truebooker-auth-bypass/</link><pubDate>Wed, 16 Sep 2026 05:46:26 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-truebooker-auth-bypass/</guid><description>The TrueBooker Appointment Booking and Scheduler System plugin for WordPress contains an authorization bypass vulnerability allowing unauthenticated attackers to modify arbitrary user email addresses and facilitate account takeover.</description><content:encoded><![CDATA[<p>The TrueBooker - Appointment Booking and Scheduler System plugin for WordPress is vulnerable to an authorization bypass flaw (CVE-2026-14349) affecting all versions up to and including 1.2.3. The vulnerability stems from a failure to perform adequate authorization checks on critical administrative functions. An unauthenticated attacker can exploit this flaw to update the email address associated with any user account, including those with administrator privileges. By redirecting the administrative email address to an attacker-controlled account, the adversary can initiate a standard WordPress password reset request. This mechanism allows the attacker to hijack administrative sessions, potentially leading to full site compromise, data exfiltration, and the deployment of persistent backdoors within the WordPress environment. This vulnerability is highly severe given its ease of exploitation and the direct path to privilege escalation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to gain full administrative control over the affected WordPress installation. This can result in complete site compromise, unauthorized access to sensitive booking data, customer information exfiltration, and the installation of malicious software or redirect scripts. The vulnerability impacts any organization relying on the TrueBooker plugin for scheduling, regardless of their specific industry.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Identify all WordPress installations utilizing the TrueBooker plugin.</li>
<li>Immediate remediation: Update the TrueBooker - Appointment Booking and Scheduler System plugin to the latest version as soon as a patch is released by the developer.</li>
<li>If a patch is unavailable, deactivate or remove the plugin until a secure version is confirmed.</li>
<li>Conduct an audit of administrative user accounts for unauthorized email changes or suspicious activity log entries.</li>
<li>Implement web application firewall (WAF) rules to restrict access to administrative API endpoints associated with user profile modification.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>wordpress</category><category>vulnerability</category><category>authorization-bypass</category></item></channel></rss>