OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-93548 (CVSS 8.8)

NVD · officialPublished Oct 9, 2026Risk 37/100EPSS 0.1%

The FooSales WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitled to act as the user a request names, allowing any authenticated user to have the FooSales WordPress plugin before 1.43.3 act as an arbitrary other user, including an administrator, resulting in that user's account details being exposed and their account being taken over.

CVSS
8.8
AV:NetworkAC:LowPR:LowUI:NoneC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source