← WordPress Vulnerabilities
WordPress security by component

TrueBooker

TrueBooker is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: truebooker

CVE-2026-14545: TrueBooker permits unauthenticated administrator account takeover

TrueBooker before 1.2.4 fails to verify that the caller owns the account selected by a front-end password-reset handler. An unauthenticated attacker can target an arbitrary user, set a new password and then authenticate as that account; targeting an Administrator yields full site takeover. The WPScan CNA record does not disclose the handler, request endpoint, account identifier, password parameters or vulnerable function.

PublishedJul 28, 2026
Known safe version1.2.4
Safe version
Jul 28, 2026 CVE-2026-14545
TrueBooker permits unauthenticated administrator account takeover
TrueBooker before 1.2.4 fails to verify that the caller owns the account selected by a front-end password-reset handler. An unauthenticated attacker can target an arbitrary user, set a new password and then authenticate as that account; targeting an Administrator yields full site takeover. The WPScan CNA record does not disclose the handler, request endpoint, account identifier, password parameters or vulnerable function.
1.2.4
CVE9.8
NVDPending
May 07, 2025 CVE-2025-47543
TrueBooker: Cross-site request forgery
TrueBooker is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Sep 08, 2024 CVE-2024-6925
TrueBooker: Cross-site request forgery
TrueBooker is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Sep 08, 2024 CVE-2024-6924
TrueBooker: SQL injection
TrueBooker is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8