CVE-2026-18200: FoodBoxBooker < 1.0.8 - Subscriber+ Arbitrary User Profile Update
The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FoodBoxBooker WordPress pluginto a version that resolves this vulnerability.Fixed in 1.0.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18200?
CVE-2026-18200 has a risk rating of 65, indicating a medium severity vulnerability.
How do I fix CVE-2026-18200?
To fix CVE-2026-18200, update the FoodBoxBooker WordPress plugin to version 1.0.8 or higher.
Who is affected by CVE-2026-18200?
CVE-2026-18200 affects authenticated users with Subscriber-level access and above using FoodBoxBooker versions before 1.0.8.
What type of vulnerability is CVE-2026-18200?
CVE-2026-18200 is an arbitrary user profile update vulnerability that allows unauthorized modification of user profiles.
What can attackers do with CVE-2026-18200?
Attackers exploiting CVE-2026-18200 can modify the profile details of arbitrary users, potentially including administrators.