Arbitrary File Deletion Vulnerability in FoodBakery by WordPress
CVE-2026-78530

7.7HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 October 2026

What is CVE-2026-78530?

The FoodBakery product, managed through WordPress, has a vulnerability that allows subscribers to delete arbitrary files. This poses serious risks as unauthorized file deletions can lead to data loss or website misconfigurations. It is essential for users of FoodBakery version 4.6 or lower to address this issue promptly to safeguard their assets.

Affected Version(s)

FoodBakery <= 4.6

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program
.