CVE-2026-18200

Summary

The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators.

Affected Software

VendorProductVersion RangeStatus
UnknownFoodBoxBooker0 < 1.0.8affected

Weaknesses

  • CWE-639 Authorization Bypass Through User-Controlled Key

References