External risk intelligence

FoodBoxBooker WordPress Plugin Password Reset Vulnerability Allows Full Site Takeover.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-16298

The vulnerability exists in a WordPress plugin. WordPress sites and their associated plugins are designed to be public-facing web applications, and password reset functionality is a standard, internet-accessible feature of these platforms.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security flaw has been identified in the FoodBoxBooker WordPress plugin that could allow unauthorized individuals to reset user passwords, including those of administrators, potentially leading to complete control of the website. This vulnerability, present in versions prior to 1.0.7, requires no authentication to exploit and could have significant implications for site integrity and data security.

  • Attackers can reset any user's password.
  • It allows full website control.
  • Confirm if your site uses this plugin.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a crafted request to the website's password reset functionality. This feature is often publicly accessible, meaning the attacker doesn't need any prior access or authentication to initiate the process. By manipulating the password reset request, an attacker can gain control of a user's account, potentially leading to full control of the website.

  • Unauthenticated access to the site is required.
  • An attacker can trigger the vulnerability via a password reset request.
  • Risk of full website takeover and data compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to reset the passwords of any user on a FoodBoxBooker WordPress site, including administrators. This could result in unauthorized control over the entire website when the plugin is in use.

  • Arbitrary user accounts could be compromised.
  • Attackers could reset user passwords remotely.
  • Complete website takeover is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

To address this critical vulnerability, application owners and platform teams are likely responsible for identifying all instances of the affected WordPress plugin. The first practical step is to confirm if these instances are internet-facing or accessible and then to engage with the accountable owners to plan remediation, prioritizing business-critical systems.

  • Application owners should investigate plugin deployment.
  • Verify if the plugin is exposed to the internet.
  • Coordinate remediation with site administrators.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the FoodBoxBooker WordPress plugin?

FoodBoxBooker is a specialized plugin for the WordPress content management system, typically used by websites to manage food ordering, reservation scheduling, or booking workflows. It extends standard WordPress capabilities to handle customer interactions and service availability directly within the site environment.

What does CVE-2026-16298 mean in plain English?

This vulnerability is classified as CWE-269, which involves improper privilege management. Specifically, the plugin fails to verify the legitimacy of password reset requests. Because the system trusts these requests without checking them, an unauthorized user can force a password change for any account, including high-privilege administrators, effectively bypassing security barriers.

How can an attacker trigger this vulnerability?

An attacker initiates the process by sending a manipulated password reset request to the targeted website. This exploit does not require the attacker to have an existing account, legitimate credentials, or prior access to the system. Simply navigating to the plugin's public-facing password reset form and submitting a crafted request is sufficient to trigger the flaw.

Why should I care about this if my site is internal?

According to Halo Surface Signal, this vulnerability is particularly concerning because WordPress plugins and their password reset functions are designed to be internet-facing by default. Even if you consider your site internal, any path accessible over a network can be leveraged. If the login or reset pages are reachable via a browser, the site remains at risk.

Do I need to update my software to fix this?

Yes. The first step is to check your WordPress dashboard to determine if you are running a version of the FoodBoxBooker plugin earlier than 1.0.7. If you are, you must update to 1.0.7 or later immediately. If an update is unavailable, disabling or removing the plugin until a secure version is deployed is the primary way to mitigate the risk of account takeover.

References