Get real-time updates on Telegram
Verified
CVE-2026-93548: FooSales 0 to before 1.43.3
Affected technology
FooSales · 0 to before 1.43.3
Vendor not specified by the source
Description’s affected range: before 1.43.3 does not verify that an authenticated caller is entitled to act as the user a request names
Component: Not specified by the source
What an attacker can do
Any authenticated user can have the FooSales WordPress plugin before 1.43.3 act as an arbitrary other user, including an administrator, resulting in that user's account details being exposed and their account being taken over.
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-09 12:23:46.868896+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-09 12:21:30.679837+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-93548.html