Unauthorized Data Access and Modification in FoodBakery WordPress Theme by FoodBakery
CVE-2024-12920
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 March 2025
What is CVE-2024-12920?
The FoodBakery | Delivery Restaurant Directory WordPress Theme is susceptible to unauthorized access and data modification due to inadequate capability checks across various functions. This vulnerability allows authenticated attackers, including those with Subscriber-level access, to perform a series of potentially harmful actions such as deleting arbitrary files, altering theme options, exporting and importing widget settings, generating and restoring backups, and resetting all theme options. Such exploitation can lead to severe security breaches, putting sensitive data at risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FoodBakery | Delivery Restaurant Directory WordPress Theme * <= 4.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved