كل الثغرات
متوسطCVE-2026-11802
ثغرة تفويض مفقودة في نظام طلبات الطعون FoodBook Lite
32
درجة الخطر
5.3
CVSS
0%
EPSS
CWE-862
التصنيف
الوصف
تسمح الثغرة للمهاجمين غير المصادقين بإنشاء حسابات مستخدمين بدور 'customer' واست_cookies المصادقة حتى عند تعطيل التسجيل من قبل المسؤول.
يجري إعداد تحليل الذكاء الاصطناعي لهذه الثغرة… سيظهر قريباً.
المعالجة الموصى بها
حدّث المنتج المتأثّر إلى أحدث إصدار مُصحَّح من المورّد، وراجع المصادر الرسمية أدناه للحصول على المعالجة الدقيقة.
المصادر والمراجع الرسمية
https://plugins.trac.wordpress.org/browser/foodbook-light-online-food-ordering-system/tags/1.5.6/inc/class-components-ajax.php#L18 https://plugins.trac.wordpress.org/browser/foodbook-light-online-food-ordering-system/tags/1.5.6/inc/class-components-ajax.php#L21 https://plugins.trac.wordpress.org/browser/foodbook-light-online-food-ordering-system/tags/1.5.6/inc/class-components-ajax.php#L68 https://plugins.trac.wordpress.org/browser/foodbook-light-online-food-ordering-system/tags/1.5.6/inc/class-components-ajax.php#L86 https://plugins.trac.wordpress.org/browser/foodbook-light-online-food-ordering-system/tags/1.5.7/inc/class-components-ajax.php#L39 https://plugins.trac.wordpress.org/browser/foodbook-light-online-food-ordering-system/tags/1.5.7/inc/class-components-ajax.php#L67-L73 https://plugins.trac.wordpress.org/browser/foodbook-light-online-food-ordering-system/tags/1.5.7/inc/helper-functions.php#L724-L725 https://www.wordfence.com/threat-intel/vulnerabilities/id/8b67557c-785f-433b-8e5b-fcc0bda14892?source=cve NVD — CVE-2026-11802
نُشرت: 2026-07-14