CVE Vulnerabilities

CVE-2026-14545

Improper Privilege Management

Published: Jul 28, 2026 | Modified: Jul 28, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a users password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Potential Mitigations

References