Unrated severityNVD Advisory· Published Aug 10, 2026
CVE-2026-16298
CVE-2026-16298
Description
The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
Affected products
1- Range: <1.0.7
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.