Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4w8m-c933-mrf8

Опубликовано: 10 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

EPSS

Процентиль: 28%
0.00341
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 месяца назад

The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

EPSS

Процентиль: 28%
0.00341
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-269