plugin

Wp Foodbakery Vulnerabilities

10 known security issues reported for the Wp Foodbakery WordPress plugin. Most recent disclosed Jul 21, 2026.

4 critical 3 high 3 medium

Running Wp Foodbakery on your site? Check whether your installed version is affected.

Scan your site free

WP Foodbakery <= 4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via via delete_locations_backup_file AJAX Action

high

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to delet...

CVSS:
8.1
Affected:
up to 4.9
Fix:
No patched version reported
Disclosed:
Jul 21, 2026

CVE-2026-15802 on NVD →

WP FoodBakery <= 3.3 - Unauthenticated PHP Object Injection

critical

The WP FoodBakery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via...

CVSS:
9.8
Affected:
up to 3.3
Fix:
No patched version reported
Disclosed:
Apr 21, 2025

CVE-2025-32927 on NVD →

FoodBakery | Delivery Restaurant Directory WordPress Theme <= 4.7 - Cross-Site Request Forgery in Multiple Functions

high

The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. This is due to missing or incorrect nonce validation on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save, expor...

CVSS:
8.8
Affected:
up to 4.7
Fix:
No patched version reported
Disclosed:
Mar 18, 2025

CVE-2024-13933 on NVD →

FoodBakery | Delivery Restaurant Directory WordPress Theme <= 4.7 - Missing Authorization in Multiple Functions

high

The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save, export_widget_settings, ajax_import_widge...

CVSS:
8.8
Affected:
up to 4.7
Fixed in:
4.8
Disclosed:
Mar 18, 2025

CVE-2024-12920 on NVD →

WP Foodbakery <= 4.7 - Unauthenticated Arbitrary File Upload

critical

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_profile_image' function in versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server whi...

CVSS:
9.8
Affected:
up to 4.7
Fixed in:
4.8
Disclosed:
Feb 10, 2025

CVE-2024-13011 on NVD →

WP Foodbakery <= 4.7 - Unauthenticated Privilege Escalation in foodbakery_registration_validation

critical

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible for unauthenticated attackers to register on the site as an adminis...

CVSS:
9.8
Affected:
up to 4.7
Fixed in:
4.8
Disclosed:
Feb 10, 2025

CVE-2025-0180 on NVD →

WP Foodbakery <= 4.8 - Authentication Bypass in foodbakery_parse_request

critical

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.8. This is due to the plugin not properly validating a user's identity prior to setting the current user and their authentication cookie. This makes it possible for unauthenticated a...

CVSS:
9.8
Affected:
up to 4.8
Fix:
No patched version reported
Disclosed:
Feb 10, 2025

CVE-2025-0181 on NVD →

WP Foodbakery <= 4.8 - Reflected Cross-Site Scripting

medium

The WP Foodbakery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on the 'search_type' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...

CVSS:
6.1
Affected:
up to 4.8
Fix:
No patched version reported
Disclosed:
Feb 10, 2025

CVE-2024-13010 on NVD →

FoodBakery | Delivery Restaurant Directory WordPress Theme <= 2.1 - Reflected Cross-Site Scripting

medium

The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakery_radius parameter before outputting it back in the response, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.

CVSS:
6.1
Affected:
up to 2.1
Fixed in:
2.2
Disclosed:
Jun 14, 2021

CVE-2021-24389 on NVD →

FoodBakery <= 1.9 - Reflected Cross-Site Scripting

medium

The FoodBakery theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9 due to insufficient input sanitization and output escaping on the 'location' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if t...

CVSS:
6.1
Affected:
up to 1.9
Fixed in:
2.0
Disclosed:
Jul 24, 2020

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database