SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-14545

CRITICAL · CVSS 9.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The TrueBooker WordPress plugin prior to version 1.2.4 is vulnerable due to inadequate validation of account ownership during password resets, enabling unauthenticated attackers to reset passwords for any user account, including administrators. This critical flaw poses a significant risk of complete site takeover, making it essential for all WordPress site administrators using this plugin to prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-14545
Severity
CRITICAL
CVSS
9.8
EPSS
0.29%
WordPress

Original NVD Description

The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.