ThreatCluster

Critical WordPress Plugin Vulnerability Allows Admin Password Reset Without Authentication

First seen 9 Aug 2026, 21:19 UTC Ciberseguridadlatam 76% similarity 73

Article Content

Browse articles
ThreatCluster

A critical vulnerability (CVE-2026-14365) in the TrueBooker plugin for WordPress enables attackers to reset administrator passwords without authentication. This flaw affects all sites using the TrueBooker – Appointment Booking and Scheduler System plugin, allowing unauthorized access and potential total control of the affected sites. The vulnerability was published on August 7, 2026, and is classified as critical by the National Vulnerability Database. Attackers can exploit this flaw remotely, posing a significant risk to website security. Site administrators are urged to take immediate action to mitigate this risk. The exact number of affected sites is currently unknown, but the potential impact is substantial given the plugin's widespread use.

Key Points: • CVE-2026-14365 allows password resets without authentication in TrueBooker plugin. • The vulnerability affects all WordPress sites using the TrueBooker plugin. • Immediate action is required by site administrators to secure their systems.

ThreatCluster AI How this analysis works

Timeline

2026-08-07
CVE-2026-14365 published
National Vulnerability Database published a critical vulnerability in TrueBooker plugin allowing unauthorized password resets.
Ciberseguridadlatam
2026-08-09
Security alert issued
Security experts warn that the TrueBooker plugin vulnerability exposes sites to total control by attackers.
Ciberseguridadlatam

Community

Browse all →

Tracked Entities in This Story