Unauthorized Data Access and Modification in FoodBakery WordPress Theme by FoodBakery
CVE-2024-12920
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 March 2025
What is CVE-2024-12920?
The FoodBakery | Delivery Restaurant Directory WordPress Theme is susceptible to unauthorized access and data modification due to inadequate capability checks across various functions. This vulnerability allows authenticated attackers, including those with Subscriber-level access, to perform a series of potentially harmful actions such as deleting arbitrary files, altering theme options, exporting and importing widget settings, generating and restoring backups, and resetting all theme options. Such exploitation can lead to severe security breaches, putting sensitive data at risk.
Affected Version(s)
FoodBakery | Delivery Restaurant Directory WordPress Theme * <= 4.7