VYPR
Critical severity9.8NVD Advisory· Published Aug 10, 2026· Updated Aug 26, 2026

CVE-2026-16298

CVE-2026-16298

Description

The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

1