{"id":"CVE-2026-93548","title":"The FooSales  WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitled to act as the user a request names, allowing any authenticated user to have the FooSales  WordPress plugin before 1.43.3 act as an arbi…","summary":"The FooSales  WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitled to act as the user a request names, allowing any authenticated user to have the FooSales  WordPress plugin before 1.43.3 act as an arbi…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-269"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T15:17:20.140","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93548","references":[{"url":"https://wpscan.com/vulnerability/7d9238eb-f56e-49db-a804-7505f59fca5c/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00132,"epssPercentile":0.02407,"ingestedAt":"2026-10-09T07:28:22.268Z","slug":"CVE-2026-93548","body":"## Overview\n\nThe FooSales  WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitled to act as the user a request names, allowing any authenticated user to have the FooSales  WordPress plugin before 1.43.3 act as an arbitrary other user, including an administrator, resulting in that user's account details being exposed and their account being taken over.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":218548,"id":"CVE-2026-93548","ts":1791561813956,"field":"cvss","old":null,"new":"8.8"},{"seq":218547,"id":"CVE-2026-93548","ts":1791561813956,"field":"severity","old":"none","new":"high"}]}