Privilege Escalation Vulnerability in WP Foodbakery Plugin for WordPress
CVE-2025-0180
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 11 February 2025
Badges
What is CVE-2025-0180?
The WP Foodbakery plugin for WordPress exhibits a vulnerability that allows unauthenticated attackers to register as administrators. This weakness arises from inadequate restrictions on user meta fields during profile registration, which enables attackers to exploit the registration process and gain elevated privileges within the site.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Foodbakery * <= 4.7
News Articles
Fix CVE-2025-0180: WP Foodbakery Security Guide
Learn how to protect your WordPress site from the critical CVE-2025-0180 vulnerability in WP Foodbakery plugin. Step-by-step security guide for admins.
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by TheSecMaster
Vulnerability published
Vulnerability Reserved