Arbitrary File Deletion Vulnerability in FoodBakery by WordPress
CVE-2026-78530
7.7HIGH
What is CVE-2026-78530?
The FoodBakery product, managed through WordPress, has a vulnerability that allows subscribers to delete arbitrary files. This poses serious risks as unauthorized file deletions can lead to data loss or website misconfigurations. It is essential for users of FoodBakery version 4.6 or lower to address this issue promptly to safeguard their assets.
Affected Version(s)
FoodBakery <= 4.6
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program