Unauthorized Data Access and Modification in FoodBakery WordPress Theme by FoodBakery
CVE-2024-12920

8.8HIGH

What is CVE-2024-12920?

The FoodBakery | Delivery Restaurant Directory WordPress Theme is susceptible to unauthorized access and data modification due to inadequate capability checks across various functions. This vulnerability allows authenticated attackers, including those with Subscriber-level access, to perform a series of potentially harmful actions such as deleting arbitrary files, altering theme options, exporting and importing widget settings, generating and restoring backups, and resetting all theme options. Such exploitation can lead to severe security breaches, putting sensitive data at risk.

Affected Version(s)

FoodBakery | Delivery Restaurant Directory WordPress Theme * <= 4.7

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucio Sá
.