User Impersonation Vulnerability in FooSales Plugin by WordPress
CVE-2026-93548
Key Information:
Badges
What is CVE-2026-93548?
The FooSales plugin for WordPress, prior to version 1.43.3, contains a serious vulnerability that allows any authenticated user to impersonate other users, including administrators. This flaw arises from the lack of proper verification to establish if a user is authorized to act on behalf of another. As a result, an attacker can gain unauthorized access to sensitive account details, potentially leading to full account takeover. It's crucial for users of the affected versions to update promptly to protect their sites from exploitation.
Affected Version(s)
FooSales 0 < 1.43.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.