Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-16298

Опубликовано: 10 авг. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

EPSS

Процентиль: 28%
0.00341
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 9.8
github
около 1 месяца назад

The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

EPSS

Процентиль: 28%
0.00341
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-269