What is CVE-2026-18200?
The FoodBoxBooker WordPress plugin vulnerability allows any authenticated user with Subscriber-level access or higher to modify profile details of arbitrary users, including administrators. Updating the plugin to version 1.0.8 is recommended.
Azərbaycanca: FoodBoxBooker WordPress plaqinindəki boşluq autentifikasiya olunmuş istənilən Subscriber və yuxarı səviyyəli istifadəçiyə, o cümlədən administratorların profil məlumatlarını dəyişməyə imkan verir. Plaqini 1.0.8 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
From what privilege level can the CVE-2026-18200 vulnerability in the FoodBoxBooker plugin be exploited?
The vulnerability can be exploited by any authenticated user with Subscriber-level access or higher.
To which version should the FoodBoxBooker plugin be updated to fix CVE-2026-18200?
The plugin should be updated to version 1.0.8.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.