What is CVE-2026-16298?
The FoodBoxBooker WordPress plugin before version 1.0.7 has a vulnerability where the password reset request is not properly validated. This allows unauthenticated attackers to reset the password of any user, including administrators, potentially leading to a full site takeover. Immediate update to the latest version is required.
Azərbaycanca: FoodBoxBooker WordPress plaqinində (1.0.7-dən əvvəl) zəiflik aşkarlanıb. Doğrulama olmadığı üçün autentifikasiya olunmamış hücumçular istənilən istifadəçinin, o cümlədən adminin şifrəsini sıfırlaya bilər ki, bu da saytın tam ələ keçirilməsinə səbəb ola bilər. Dərhal plaqini son versiyaya yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
How to protect against the user password reset vulnerability in the FoodBoxBooker WordPress plugin?
Since the vulnerability exists in versions before 1.0.7, immediate update to the latest version is required.
What does the CVE-2026-16298 vulnerability allow an unauthenticated attacker to do?
Due to lack of validation, unauthenticated attackers can reset the password of any user, including administrators, potentially leading to a full site takeover.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.