What is CVE-2026-14365?
This vulnerability exists in all versions of the TrueBooker – Appointment Booking and Scheduler System plugin, allowing unauthenticated users to bypass authorization checks and perform actions. The flaw stems from the plugin's failure to properly verify user permissions. Affected sites should immediately update or deactivate the plugin.
Azərbaycanca: Bu boşluq TrueBooker – Appointment Booking and Scheduler System plagininin bütün versiyalarında mövcuddur və autentifikasiya olunmamış istifadəçilərə icazə yoxlamasını keçərək əməliyyat icra etməyə imkan verir. Plaginin düzgün authorization yoxlaması etməməsi səbəbindən zəiflik yaranır. Təsirə məruz qalan saytlar dərhal plaqini yeniləməli və ya deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Does an attacker need to be logged in to exploit CVE-2026-14365?
No, this vulnerability allows unauthenticated users to bypass authorization checks and perform actions.
What is the root cause of CVE-2026-14365?
The flaw stems from the TrueBooker – Appointment Booking and Scheduler System plugin's failure to properly verify user permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.