Critical WordPress Plugin Vulnerability Allows Admin Password Reset Without Authentication
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability (CVE-2026-14365) in the TrueBooker plugin for WordPress enables attackers to reset administrator passwords without authentication. This flaw affects all sites using the TrueBooker – Appointment Booking and Scheduler System plugin, allowing unauthorized access and potential total control of the affected sites. The vulnerability was published on August 7, 2026, and is classified as critical by the National Vulnerability Database. Attackers can exploit this flaw remotely, posing a significant risk to website security. Site administrators are urged to take immediate action to mitigate this risk. The exact number of affected sites is currently unknown, but the potential impact is substantial given the plugin's widespread use.
Key Points: • CVE-2026-14365 allows password resets without authentication in TrueBooker plugin. • The vulnerability affects all WordPress sites using the TrueBooker plugin. • Immediate action is required by site administrators to secure their systems.