๐Ÿ” CVE Alert

CVE-2026-93548

UNKNOWN 0.0

FooSales < 1.43.3 - Subscriber+ Privilege Escalation via User Impersonation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The FooSales WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitled to act as the user a request names, allowing any authenticated user to have the FooSales WordPress plugin before 1.43.3 act as an arbitrary other user, including an administrator, resulting in that user's account details being exposed and their account being taken over.

Vendor unknown
Product foosales
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for unknown foosales

Be the first to know when new unknown vulnerabilities affecting unknown foosales are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / FooSales
0 < 1.43.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/7d9238eb-f56e-49db-a804-7505f59fca5c/

Credits

Naoki Kawahigashi WPScan