CVE-2026-11802
Last modified
CVE-2026-11802 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5.6. The registration() function, accessible via the wp_ajax_nopriv_registration_action AJAX action, lacks any nonce verification or capability check, and does not check the WordPress users_can_register option before calling wp_insert_user(). EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5.6. The registration() function, accessible via the wp_ajax_nopriv_registration_action AJAX action, lacks any nonce verification or capability check, and does not check the WordPress users_can_register option before calling wp_insert_user(). This makes it possible for unauthenticated attackers to create new user accounts with the 'customer' role and receive authentication cookies, even when the site administrator has explicitly disabled user registration.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| themelooks | FoodBook Lite – Online Food Ordering System | <= 1.5.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-11802?
How severe is CVE-2026-11802?
How do I fix CVE-2026-11802?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-11793A stack buffer overflow flaw was found in 389 Directory Serv…4.9
- CVE-2026-11794The Advanced Form Integration — Connect Forms to 200+ Apps W…8.1
- CVE-2026-11798The Social Share, Social Login and Social Comments Plugin – …6.1
- CVE-2026-11799UXSS in Focus for iOS / Klar Webkit navigation. This vulnera…7.5
- CVE-2026-1180A flaw was identified in Keycloak’s OpenID Connect Dynamic C…5.8
- CVE-2026-11800A flaw was found in Keycloak. This JWT algorithm confusion v…8.1
- CVE-2026-11803A maliciously crafted PDF file, when parsed through Autodesk…7.8
- CVE-2026-11804Improper handling of insufficient permissions or privileges …5.2
- CVE-2026-11806IBM WebSphere Application Server - Liberty 17.0.0.3 through …7.5
- CVE-2026-11807A missing authorization vulnerability was found in the Event…9.6
- CVE-2026-11809The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.…3.7
- CVE-2026-1181Altium 365 workspace endpoints were configured with an overl…9
Are you affected by CVE-2026-11802?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
