Feed/CVE-2026-14545
CVE-2026-14545

CVE-2026-14545

Published Jul 28, 2026·Updated Jul 28, 2026

NVD Description

The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free