Junglewise Threat Intelligence

CVE-2026-11802: themelooks FoodBook Lite missing authorization in registration function

CVE-2026-11802 · Severity: medium · CVSS 5.3 · Published 2026-07-14

Executive brief

The FoodBook Lite plugin for WordPress, which provides online food ordering capabilities, contains a security flaw that allows unauthorized user registration. An attacker can create a new 'customer' account on the website even if the site administrator has disabled new user registrations. This could lead to unauthorized access to customer-only features and potential spam or data management issues for the site owner.

Technical details

The FoodBook Lite plugin for WordPress is vulnerable to missing authorization due to a lack of security checks in the registration() function. This function is accessible via the wp_ajax_nopriv_registration_action AJAX action and fails to implement nonce verification, capability checks, or a check against the WordPress 'users_can_register' option before calling wp_insert_user(). Consequently, unauthenticated remote attackers can register new accounts with 'customer' privileges and obtain authentication cookies. The issue is addressed in version 1.5.7.

Affected products

  • themelooks FoodBook Lite – Online Food Ordering System up to, and including, 1.5.6

Timeline

  • 2026-07-14: advisory: NVD publication date
  • 2026-07-13: disclosed: Wordfence disclosure date

References