WordPress Plugin Vulnerabilities

FoodBoxBooker < 1.0.7 - Unauthenticated Arbitrary Password Reset

Description

The plugin does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

Proof of Concept

Affects Plugins

Fixed in 1.0.7

References

Classification

Miscellaneous

Original Researcher
moonge
Submitter
moonge
Verified
Yes

Timeline

Publicly Published
2026-08-05 (about 5 days ago)
Added
2026-08-05 (about 4 days ago)
Last Updated
2026-08-07 (about 2 days ago)

Other