FoodBakery WordPress Theme Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the FoodBakery | Delivery Restaurant Directory WordPress Theme, affecting all versions through 4.7. The vulnerability arises from inadequate nonce validation in several functions, allowing unauthenticated attackers to delete files, modify theme options, and manage widget data by tricking an administrator into responding to a forged request.

Impact

Exploitation of this vulnerability could lead to unauthorized file deletions and modifications of theme and widget settings.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.