Junglewise Threat Intelligence

CVE-2026-15802: Chimpstudio WP Foodbakery arbitrary file deletion in delete_locations_backup_file_callback

CVE-2026-15802 · Severity: high · CVSS 8.1 · Published 2026-07-22

Executive brief

WP Foodbakery, a WordPress plugin used for restaurant and bakery websites, contains a security flaw that allows users with basic account access to delete files on the web server. By deleting critical system files, an attacker can crash the website or gain full control over the server to execute malicious code. This poses a significant risk to data integrity and overall site availability.

Technical details

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to a path traversal flaw (CWE-23) in the 'delete_locations_backup_file_callback' function. The vulnerability stems from insufficient validation of user-supplied file paths, allowing authenticated attackers with subscriber-level privileges or higher to delete files outside of the intended directory. By targeting critical configuration files like 'wp-config.php', an attacker can trigger a site reset or otherwise manipulate the environment to achieve remote code execution. The issue affects all versions of the plugin up to and including 4.9.

Affected products

  • Chimpstudio WP Foodbakery up to, and including, 4.9

Timeline

  • 2026-07-22: advisory: NVD published the CVE record based on Wordfence data.

References