The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a users password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.