What is CVE-2026-14545?
The TrueBooker WordPress plugin before 1.2.4 fails to validate account ownership when resetting a user's password. This vulnerability allows unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What does the CVE-2026-14545 vulnerability in the TrueBooker WordPress plugin lead to?
It allows unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.
Which versions of the TrueBooker plugin are affected by CVE-2026-14545?
Versions before 1.2.4 are affected.
See also6
grounded ✓NVD ↗
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.