CVE-2026-14545
Vulnerability Description
The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.
Vulnerability Details
Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
TrueBooker
Discussion (0)
Add Comment
No comments yet. Be the first!