CVE-2026-16298

9.8

FoodBoxBooker · FoodBoxBooker

The FoodBoxBooker WordPress plugin fails to validate password reset requests, enabling unauthenticated attackers to reset passwords for any user, including administrators.

Executive summary

A critical authentication flaw in the FoodBoxBooker plugin permits unauthenticated attackers to perform unauthorized password resets, leading to complete site takeover.

Vulnerability

This is an improper privilege management vulnerability stemming from insufficient validation of password reset requests. An unauthenticated attacker can manipulate these requests to change the credentials of any account on the system.

Business impact

With a CVSS score of 9.8, this vulnerability represents an existential threat to the integrity and availability of the affected WordPress site. An attacker who gains administrative access can exfiltrate sensitive data, modify content, and conduct further malicious activities, leading to total loss of control over the application.

Remediation

Immediate Action: Update the FoodBoxBooker plugin to version 1.0.7 or later as soon as possible.

Proactive Monitoring: Audit user account activity for unexpected password changes or administrative logins that correlate with unauthorized reset attempts.

Compensating Controls: Implement strict rate limiting on password reset endpoints and monitor for anomalous spikes in reset requests originating from single or distributed IP addresses.

Exploitation status

Public Exploit Available: No confirmed public exploit is available in the provided data.

Analyst recommendation

The severity of this vulnerability necessitates immediate action to protect user accounts and administrative access. Organizations must apply the 1.0.7 patch immediately to close the authentication bypass vector and prevent potential site takeover.