CVE-2026-16298: Unknown Foodboxbooker
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
Affected products
- Unknown Foodboxbooker: before 1.0.7 (fixed in 1.0.7)
Published 2026-08-10. Last modified 2026-08-26.