Executive brief
FoodBoxBooker is a WordPress booking plugin that manages account functionality for restaurant customers. The plugin contains a critical flaw in its password reset mechanism that allows attackers to reset passwords for any user, including administrators, without authentication or special permissions. This vulnerability enables complete takeover of affected WordPress sites, giving attackers full administrative access to modify content, user accounts, and site settings.
Technical details
The FoodBoxBooker plugin before version 1.0.7 fails to properly validate CSRF nonces and user authorization in two password reset endpoints (fbbttm_resetpass and account_edit_formsubmit AJAX actions). The vulnerability affects all users because the plugin's nonces are scraped from a publicly accessible "My account" page that requires no authentication. Path 1 (versions ≤1.0.5) exploits an empty user_activation_key field to reset any user's password; Path 2 (versions ≤1.0.6) bypasses email validation. No authentication or special privileges are required—the attacker only needs network access and can target administrator accounts directly. The fix is available in version 1.0.7.
Affected products
- FoodBoxBooker FoodBoxBooker before 1.0.7
Timeline
- 2026-08-05: disclosed
- 2026-01-01: patched: Fixed in version 1.0.7
- 2026-08-10: advisory