WordPress Plugin Vulnerabilities

FoodBoxBooker < 1.0.8 - Subscriber+ Arbitrary User Profile Update

Description

The plugin does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators.

Proof of Concept

Affects Plugins

Fixed in 1.0.8

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Erwan LR (WPScan)
Submitter
Erwan LR (WPScan)
Verified
Yes

Timeline

Publicly Published
2026-08-07 (about 3 days ago)
Added
2026-08-07 (about 2 days ago)
Last Updated
2026-08-07 (about 2 days ago)

Other