CRITICAL
9.8 CVE-2026-14349 Published 16 Sept 2026
WordPress TrueBooker Plugin Authorization Bypass
Worried this affects one of your servers?
The TrueBooker plugin for WordPress is affected by an authorization bypass vulnerability.
TrueBooker versions up to 1.2.3 do not properly verify user authorization, allowing unauthenticated attackers to modify email addresses of user accounts, including administrators.
This can be exploited to reset passwords and gain unauthorized access to accounts.
Reference: CVE-2026-14349 on NVD
← Back to Security News