Executive brief
WP Foodbakery, a WordPress plugin used for restaurant and bakery websites, contains a security flaw that allows users with basic account access to delete files on the web server. By deleting critical system files, an attacker can crash the website or gain full control over the server to execute malicious code. This poses a significant risk to data integrity and overall site availability.
Technical details
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to a path traversal flaw (CWE-23) in the 'delete_locations_backup_file_callback' function. The vulnerability stems from insufficient validation of user-supplied file paths, allowing authenticated attackers with subscriber-level privileges or higher to delete files outside of the intended directory. By targeting critical configuration files like 'wp-config.php', an attacker can trigger a site reset or otherwise manipulate the environment to achieve remote code execution. The issue affects all versions of the plugin up to and including 4.9.
Affected products
- Chimpstudio WP Foodbakery up to, and including, 4.9
Timeline
- 2026-07-22: advisory: NVD published the CVE record based on Wordfence data.