Filtered by vendor Themelooks
Subscriptions
Filtered by product Foodbook Lite – Online Food Ordering System
Subscriptions
Total
1 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-11802 | 2 Themelooks, Wordpress | 2 Foodbook Lite – Online Food Ordering System, Wordpress | 2026-07-27 | 5.3 Medium |
| The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5.6. The registration() function, accessible via the wp_ajax_nopriv_registration_action AJAX action, lacks any nonce verification or capability check, and does not check the WordPress users_can_register option before calling wp_insert_user(). This makes it possible for unauthenticated attackers to create new user accounts with the 'customer' role and receive authentication cookies, even when the site administrator has explicitly disabled user registration. | ||||
Page 1 of 1.