The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
https://wpscan.com/vulnerability/d554361c-e6c7-4843-a9cc-005b08685a5b/