← WordPress Vulnerabilities
WordPress security by component

WP Foodbakery

WP Foodbakery is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Jul 22, 2026; the highest CVE/CNA score is 9.8.

Theme slug: wp-foodbakery

CVE-2026-15802: WP Foodbakery subscribers can delete arbitrary server files

WP Foodbakery 4.9 and earlier does not adequately constrain the file path handled by delete_locations_backup_file_callback. Any authenticated user, including a subscriber, can abuse the vulnerable operation to delete files writable by the PHP process. Deleting a critical file such as wp-config.php can take the site offline and may open a path to full site compromise.

PublishedJul 22, 2026
Known safe version> 4.9
Safe version
Jul 22, 2026 CVE-2026-15802
WP Foodbakery subscribers can delete arbitrary server files
WP Foodbakery 4.9 and earlier does not adequately constrain the file path handled by delete_locations_backup_file_callback. Any authenticated user, including a subscriber, can abuse the vulnerable operation to delete files writable by the PHP process. Deleting a critical file such as wp-config.php can take the site offline and may open a path to full site compromise.
> 4.9
CVE8.1
NVDPending
Feb 11, 2025 CVE-2025-0181
FoodBakery: Privilege escalation or authentication bypass
FoodBakery is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Feb 11, 2025 CVE-2025-0180
FoodBakery: Privilege escalation or authentication bypass
FoodBakery is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Feb 10, 2025 CVE-2024-13011
FoodBakery: Dangerous file upload
FoodBakery is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE9.8
NVDPending
Feb 10, 2025 CVE-2024-13010
FoodBakery: Cross-site scripting
FoodBakery is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending