CVE-2026-16298: FoodBoxBooker < 1.0.7 - Unauthenticated Arbitrary Password Reset
The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16298?
CVE-2026-16298 has a severity score of 89, indicating a critical vulnerability.
What does CVE-2026-16298 allow attackers to do?
CVE-2026-16298 allows unauthenticated attackers to reset the passwords of arbitrary users in the FoodBoxBooker plugin.
How do I fix CVE-2026-16298?
To fix CVE-2026-16298, update the FoodBoxBooker plugin to version 1.0.7 or later.
Who is affected by CVE-2026-16298?
CVE-2026-16298 affects all versions of the FoodBoxBooker plugin before 1.0.7, allowing potential attacks on any WordPress site using it.
What are the potential consequences of CVE-2026-16298?
The potential consequences of CVE-2026-16298 include unauthorized password resets and full site takeovers by attackers.