CVE-2026-18200 PUBLISHED

FoodBoxBooker < 1.0.8 - Subscriber+ Arbitrary User Profile Update

Assigner: WPScan
Reserved: 29.07.2026 Published: 10.08.2026 Updated: 10.08.2026

The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators.

Product Status

Vendor Unknown
Product FoodBoxBooker
Versions Default: unaffected
  • affected from 0 to 1.0.8 (excl.)

Credits

  • Erwan LR (WPScan) finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE