<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>TrueBooker – Appointment Booking and Scheduler System (1.2.3) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/truebooker--appointment-booking-and-scheduler-system-1.2.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 07 Aug 2026 05:30:43 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/truebooker--appointment-booking-and-scheduler-system-1.2.3/feed.xml" rel="self" type="application/rss+xml"/><item><title>Account Takeover Vulnerability in TrueBooker WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-08-truebooker-ato/</link><pubDate>Fri, 07 Aug 2026 05:30:43 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-truebooker-ato/</guid><description>An unauthenticated account takeover vulnerability (CVE-2026-14364) in the TrueBooker plugin allows attackers to reset arbitrary user passwords due to missing identity validation.</description><content:encoded><![CDATA[<p>The TrueBooker - Appointment Booking and Scheduler System plugin for WordPress (versions 1.2.3 and below) contains a critical security flaw categorized as CWE-640: Weak Password Recovery Mechanism for Forgotten Password. The vulnerability stems from the plugin's failure to properly validate a user's identity during the password reset workflow. Because the identity check is absent, an unauthenticated attacker can supply a target user's identifier - such as an administrator account - to the password reset endpoint, triggering a password change or reset without authorization. This allows for full account takeover and subsequent persistent access to the WordPress environment. Given the critical CVSS 3.1 score of 9.8, this vulnerability poses a severe risk to any organization utilizing the plugin for scheduling services.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs reconnaissance to identify sites running the TrueBooker plugin.</li>
<li>Attacker probes the WordPress application to locate the password reset endpoint provided by the TrueBooker plugin.</li>
<li>Attacker identifies a target user's username or email address (e.g., an administrator).</li>
<li>Attacker submits a forged password reset request to the vulnerable endpoint.</li>
<li>The plugin fails to perform server-side verification of the requestor's identity, accepting the reset request.</li>
<li>The plugin updates the password or facilitates a reset for the targeted account.</li>
<li>Attacker logs in to the application as the compromised user.</li>
<li>Attacker gains full administrative control, potentially deploying further backdoors or exfiltrating sensitive appointment data.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to a total account takeover, granting attackers administrative access to the WordPress site. Potential consequences include unauthorized access to customer appointment data, modification of site content, installation of web shells for persistent access, and the potential for lateral movement within the hosting infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the TrueBooker - Appointment Booking and Scheduler System plugin to the latest version immediately to remediate CVE-2026-14364.</li>
<li>Monitor web server logs for suspicious or high-frequency POST requests targeting password reset endpoints associated with the plugin (look for unusual source IPs or volume).</li>
<li>Conduct an audit of WordPress administrator accounts for suspicious activity or recent unauthorized password changes.</li>
<li>Disable the plugin temporarily if an immediate update is not feasible.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>wordpress</category><category>plugin</category><category>vulnerability</category><category>account-takeover</category></item></channel></rss>