Impact
The vulnerability lies in the FoodBoxBooker WordPress plugin before version 1.0.8, which fails to verify that the account being updated belongs to the user making the request. This allows any authenticated user with Subscriber or higher privileges to alter the profile details of any other user, including administrators. Such an impact can compromise confidentiality and integrity of user data, enabling an attacker to impersonate higher‑privileged accounts or inject malicious content into other users' profiles. The weakness is an example of improper access control.
Affected Systems
WordPress sites that have the FoodBoxBooker plugin installed in any version earlier than 1.0.8. The attacker requires only authentication with a Subscriber‑level account or higher; no additional privileges are needed once logged in.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑to‑moderate impact that requires authentication and affects the integrity and confidentiality of user data. The EPSS score of less than 1% shows a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The attack vector is limited to authenticated users; any logged‑in Subscriber or higher account can alter any user's profile without needing additional privileges. Consequently, the risk is primarily that an attacker can impersonate or modify user information, but the overall likelihood of exploitation remains low.
OpenCVE Enrichment