Skip to main content

WP Foodbakery WordPress Plugin Subscriber-Level Path Traversal Allows Arbitrary File Deletion Leading to RCE (CVE-2026-15802)

Scope: WP Foodbakery Plugin for WordPress Versions up to and Including 4.9 (No Patch Currently Available)

Severity: High

Disclosed July 22, 2026, CVE-2026-15802 (CVSS 8.1) in the WP Foodbakery restaurant ordering plugin allows any authenticated user with subscriber-level access, which is granted to any registered site visitor on sites with open registration, to supply path traversal sequences in the delete_locations_backup_file_callback function and delete arbitrary files on the hosting server outside the intended backup directory. Deletion of wp-config.php, the most commonly targeted file in this attack class, can under many hosting configurations trigger WordPress's setup wizard, which an attacker can then use to connect the database to an attacker-controlled instance and achieve full site takeover. No vendor patch is currently available. Organizations must immediately restrict subscriber-level and above account creation to trusted users only, consider temporarily deactivating the plugin, monitor file integrity for unexpected deletions of core WordPress files, and apply the vendor patch as soon as it is released.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.