CyberRota Analysis
AI-GeneratedThe TrueBooker WordPress plugin prior to version 1.2.4 is vulnerable due to inadequate validation of account ownership during password resets, enabling unauthenticated attackers to reset passwords for any user account, including administrators. This critical flaw poses a significant risk of complete site takeover, making it essential for all WordPress site administrators using this plugin to prioritize immediate updates to mitigate potential exploitation.
Original NVD Description
The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.