Back to CVE List

CVE-2026-14545

Vulnerability Description

The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
TrueBooker

External References

Discussion (0)

Add Comment

No comments yet. Be the first!