Impact
The FoodBoxBooker WordPress plugin prior to version 1.0.7 fails to validate password reset requests, permitting an unauthenticated attacker to set a new password for any user, including administrators. This flaw effectively bypasses authentication controls and enables full compromise of the site. The vulnerability is a broken access control flaw involving password reset functionality, corresponding to CWE-269 (Improper Authentication) and CWE-640 (Logical Error).
Affected Systems
Any WordPress site that has the FoodBoxBooker plugin installed with a version older than 1.0.7. Because the plugin’s vendor is not publicly known, any site using this plugin is potentially exposed regardless of domain or hosting provider.
Risk and Exploitability
The vulnerability permits an attacker to reset arbitrary user passwords without needing any credentials, so the primary attack vector is the WordPress web interface. The EPSS score of < 1% indicates a low likelihood of exploitation, but the CVSS score of 9.8 reflects critical severity, meaning the impact is very high. Because the vulnerability is not listed in CISA's KEV catalog, there is no published exploit yet, but the flaw still allows an attacker to take full control of the site, modify content, exfiltrate data, and potentially use the host for further malicious activity.
OpenCVE Enrichment