---
id: CVE-2026-93548
title: >-
  The FooSales  WordPress plugin before 1.43.3 does not verify that an
  authenticated caller is entitled to act as the user a request names, allowing
  any authenticated user to have the FooSales  WordPress plugin before 1.43.3
  act as an arbi…
summary: >-
  The FooSales  WordPress plugin before 1.43.3 does not verify that an
  authenticated caller is entitled to act as the user a request names, allowing
  any authenticated user to have the FooSales  WordPress plugin before 1.43.3
  act as an arbi…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T15:17:20.140'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93548'
references:
  - url: 'https://wpscan.com/vulnerability/7d9238eb-f56e-49db-a804-7505f59fca5c/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00132
epssPercentile: 0.02407
ingestedAt: '2026-10-09T07:28:22.268Z'
---

## Overview

The FooSales  WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitled to act as the user a request names, allowing any authenticated user to have the FooSales  WordPress plugin before 1.43.3 act as an arbitrary other user, including an administrator, resulting in that user's account details being exposed and their account being taken over.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
