WP Foodbakery <= 4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via via delete_locations_backup_file AJAX Action
high
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to delet...
- CVSS:
- 8.1
- Affected:
- up to 4.9
- Fix:
- No patched version reported
- Disclosed:
- Jul 21, 2026
CVE-2026-15802 on NVD →
WP FoodBakery <= 3.3 - Unauthenticated PHP Object Injection
critical
The WP FoodBakery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via...
- CVSS:
- 9.8
- Affected:
- up to 3.3
- Fix:
- No patched version reported
- Disclosed:
- Apr 21, 2025
CVE-2025-32927 on NVD →
FoodBakery | Delivery Restaurant Directory WordPress Theme <= 4.7 - Cross-Site Request Forgery in Multiple Functions
high
The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. This is due to missing or incorrect nonce validation on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save, expor...
- CVSS:
- 8.8
- Affected:
- up to 4.7
- Fix:
- No patched version reported
- Disclosed:
- Mar 18, 2025
CVE-2024-13933 on NVD →
FoodBakery | Delivery Restaurant Directory WordPress Theme <= 4.7 - Missing Authorization in Multiple Functions
high
The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save, export_widget_settings, ajax_import_widge...
- CVSS:
- 8.8
- Affected:
- up to 4.7
- Fixed in:
- 4.8
- Disclosed:
- Mar 18, 2025
CVE-2024-12920 on NVD →
WP Foodbakery <= 4.7 - Unauthenticated Arbitrary File Upload
critical
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_profile_image' function in versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server whi...
- CVSS:
- 9.8
- Affected:
- up to 4.7
- Fixed in:
- 4.8
- Disclosed:
- Feb 10, 2025
CVE-2024-13011 on NVD →
WP Foodbakery <= 4.7 - Unauthenticated Privilege Escalation in foodbakery_registration_validation
critical
The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible for unauthenticated attackers to register on the site as an adminis...
- CVSS:
- 9.8
- Affected:
- up to 4.7
- Fixed in:
- 4.8
- Disclosed:
- Feb 10, 2025
CVE-2025-0180 on NVD →
WP Foodbakery <= 4.8 - Authentication Bypass in foodbakery_parse_request
critical
The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.8. This is due to the plugin not properly validating a user's identity prior to setting the current user and their authentication cookie. This makes it possible for unauthenticated a...
- CVSS:
- 9.8
- Affected:
- up to 4.8
- Fix:
- No patched version reported
- Disclosed:
- Feb 10, 2025
CVE-2025-0181 on NVD →
WP Foodbakery <= 4.8 - Reflected Cross-Site Scripting
medium
The WP Foodbakery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on the 'search_type' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...
- CVSS:
- 6.1
- Affected:
- up to 4.8
- Fix:
- No patched version reported
- Disclosed:
- Feb 10, 2025
CVE-2024-13010 on NVD →
FoodBakery | Delivery Restaurant Directory WordPress Theme <= 2.1 - Reflected Cross-Site Scripting
medium
The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakery_radius parameter before outputting it back in the response, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.
- CVSS:
- 6.1
- Affected:
- up to 2.1
- Fixed in:
- 2.2
- Disclosed:
- Jun 14, 2021
CVE-2021-24389 on NVD →
FoodBakery <= 1.9 - Reflected Cross-Site Scripting
medium
The FoodBakery theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9 due to insufficient input sanitization and output escaping on the 'location' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if t...
- CVSS:
- 6.1
- Affected:
- up to 1.9
- Fixed in:
- 2.0
- Disclosed:
- Jul 24, 2020
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database