AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18200

MEDIUM · CVSS 4.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The FoodBoxBooker plugin for WordPress versions prior to 1.0.8 is vulnerable due to a lack of proper user verification during profile updates, enabling authenticated users with Subscriber-level access or higher to alter the profile details of any user, including administrators. This flaw poses a significant risk of unauthorized access and potential privilege escalation. WordPress site administrators and security teams should prioritize patching this vulnerability to safeguard user accounts and maintain system integrity.

CVE
CVE-2026-18200
Severity
MEDIUM
CVSS
4.3
EPSS
0.15%
WordPress

Original NVD Description

The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators.