{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/truebooker--appointment-booking-and-scheduler-system-1.2.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-14364"},{"cvss":9.8,"id":"CVE-2026-14365"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TrueBooker – Appointment Booking and Scheduler System (1.2.3)","TrueBooker – Appointment Booking and Scheduler System (\u003c= 1.2.3)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","plugin","vulnerability","account-takeover"],"_cs_type":"advisory","_cs_vendors":["themetechmount"],"content_html":"\u003cp\u003eThe TrueBooker - Appointment Booking and Scheduler System plugin for WordPress (versions 1.2.3 and below) contains a critical security flaw categorized as CWE-640: Weak Password Recovery Mechanism for Forgotten Password. The vulnerability stems from the plugin's failure to properly validate a user's identity during the password reset workflow. Because the identity check is absent, an unauthenticated attacker can supply a target user's identifier - such as an administrator account - to the password reset endpoint, triggering a password change or reset without authorization. This allows for full account takeover and subsequent persistent access to the WordPress environment. Given the critical CVSS 3.1 score of 9.8, this vulnerability poses a severe risk to any organization utilizing the plugin for scheduling services.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify sites running the TrueBooker plugin.\u003c/li\u003e\n\u003cli\u003eAttacker probes the WordPress application to locate the password reset endpoint provided by the TrueBooker plugin.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a target user's username or email address (e.g., an administrator).\u003c/li\u003e\n\u003cli\u003eAttacker submits a forged password reset request to the vulnerable endpoint.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to perform server-side verification of the requestor's identity, accepting the reset request.\u003c/li\u003e\n\u003cli\u003eThe plugin updates the password or facilitates a reset for the targeted account.\u003c/li\u003e\n\u003cli\u003eAttacker logs in to the application as the compromised user.\u003c/li\u003e\n\u003cli\u003eAttacker gains full administrative control, potentially deploying further backdoors or exfiltrating sensitive appointment data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to a total account takeover, granting attackers administrative access to the WordPress site. Potential consequences include unauthorized access to customer appointment data, modification of site content, installation of web shells for persistent access, and the potential for lateral movement within the hosting infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the TrueBooker - Appointment Booking and Scheduler System plugin to the latest version immediately to remediate CVE-2026-14364.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious or high-frequency POST requests targeting password reset endpoints associated with the plugin (look for unusual source IPs or volume).\u003c/li\u003e\n\u003cli\u003eConduct an audit of WordPress administrator accounts for suspicious activity or recent unauthorized password changes.\u003c/li\u003e\n\u003cli\u003eDisable the plugin temporarily if an immediate update is not feasible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-07T05:30:47Z","date_published":"2026-08-07T05:30:43Z","id":"https://feed.craftedsignal.io/briefs/2026-08-truebooker-ato/","summary":"An unauthenticated account takeover vulnerability (CVE-2026-14364) in the TrueBooker plugin allows attackers to reset arbitrary user passwords due to missing identity validation.","title":"Account Takeover Vulnerability in TrueBooker WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-truebooker-ato/"}],"language":"en","title":"CraftedSignal Threat Feed - TrueBooker – Appointment Booking and Scheduler System (1.2.3)","version":"https://jsonfeed.org/version/1.1"}