FoodBakery WordPress Theme Cross-Site Request Forgery Vulnerability
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the FoodBakery | Delivery Restaurant Directory WordPress Theme, affecting all versions through 4.7. The vulnerability arises from inadequate nonce validation in several functions, allowing unauthenticated attackers to delete files, modify theme options, and manage widget data by tricking an administrator into responding to a forged request.
Impact
Exploitation of this vulnerability could lead to unauthorized file deletions and modifications of theme and widget settings.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
6.4remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
