EUVD Vulnerability Catalog
EUVD-2026-80094
Severity: CRITICAL
Base Score: 9.8
CVSS Version: 3.1
Vulnerability Description
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the email address of arbitrary user accounts, including administrators, which can be leveraged to reset the account's password and gain access to it.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): None
▪
User Interaction (UI): None
▪
Scope (S): Unchanged
▪
Confidentiality Impact (C): High
▪
Integrity Impact (I): High
▪
Availability Impact (A): High
Affected Vendors & Systems
Vendor
themetechmount
References & Advisory Links
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3a61ddbc-9118-4cad-a639-7822606a3181?source=cve
- https://plugins.trac.wordpress.org/changeset?old_path=/truebooker-appointment-booking/tags/1.2.3/main/function_ajax.php&new_path=/truebooker-appointment-booking/tags/1.2.4/main/function_ajax.php
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
Wordfence
EPSS Probability
0
Known Aliases
CVE-2026-14349
Published On
2026-09-16
Last Updated
2026-09-16