PatchSiren cyber security CVE debrief
CVE-2026-15802 Chimpstudio CVE debrief
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The vulnerability has a CVSS score of 8.1 and is classified as HIGH.
- Vendor
- Chimpstudio
- Product
- WP Foodbakery
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-22
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-22
- Advisory updated
- 2026-07-22
Who should care
Users of the WP Foodbakery plugin for WordPress, particularly those with subscriber-level access and above, should be aware of this vulnerability and take immediate action to update the plugin to a patched version. Additionally, security teams and administrators responsible for WordPress installations should review and implement necessary security measures to prevent exploitation.
Technical summary
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function. This allows authenticated attackers with subscriber-level access and above to delete arbitrary files on the server, potentially leading to remote code execution when critical files such as wp-config.php are deleted. Affected product deployments should be confirmed in managed environments, and owners should be assigned for follow-up. The vulnerability has a CVSS score of 8.1 and is classified as HIGH, emphasizing the need for immediate action to update the plugin to a patched version and implement necessary security measures.
Defensive priority
High
Recommended defensive actions
- Update the WP Foodbakery plugin to a patched version
- Restrict access to the 'delete_locations_backup_file_callback' function
- Monitor server logs for suspicious file deletion activity
- Implement additional security measures to prevent remote code execution
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-22T05:17:08.820Z and has not been modified since then. The NVD entry is currently 8.1 HIGH. The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation. This vulnerability affects users with subscriber-level access and above. Evidence is limited to public CVE and NVD information.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T05:17:08.820Z and has not been modified since then.