← Πίσω στην αναζήτηση CVE

CVE-2026-11802

FoodBook Lite - Online Food Ordering System

Περιγραφή

The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5.6. The registration() function, accessible via the wp_ajax_nopriv_registration_action AJAX action, lacks any nonce verification or capability check, and does not check the WordPress users_can_register option before calling wp_insert_user(). This makes it possible for unauthenticated attackers to create new user accounts with the -customer- role and receive authentication cookies, even when the site administrator has explicitly disabled user registration.

CVSS 5.3EPSS 0.311%Κίνδυνος 0.54
Προβολή πηγής
Δημοσίευση
2026-07-14 02:16:52
Επηρεαζόμενες εκδόσεις
<=1.5.6
Τύπος
Εφαρμογή ιστού
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N