CVE-2026-18200
FoodBoxBooker < 1.0.8 - Subscriber+ Arbitrary User Profile Update
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators.
| Vendor | unknown |
| Product | foodboxbooker |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown foodboxbooker
Be the first to know when new unknown vulnerabilities affecting unknown foodboxbooker are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / FoodBoxBooker
0 < 1.0.8
References
Credits
Erwan LR (WPScan) WPScan