WP Foodbakery

WP Foodbakery has 10 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2026; 5 are fixed and 5 remain unpatched as of September 2026. Their average CVSS score is 8.3, and the most serious one scores 9.8 out of 10. Severity breakdown: 4 critical and 3 high. 2025 was the busiest year with 7 disclosures.

The most common weakness is Cross-Site Scripting, behind 3 of the records (30%). Other recurring categories include Authentication Bypass Using An Alternate Path Or Channel, Cross-Site Request Forgery (CSRF).

5 of the records (50%) have a vendor fix, while 5 remain unpatched. The oldest unresolved one dates back to 2025.

7 independent researchers contributed these findings, most of them (2) reported by István Márton.

Strategic Overview

Avg CVSSHigh
8.3/ 10
Patch Coverage50%
Open

5

Fixed

5

Get automatic notifications for all WP Foodbakery vulnerabilities before they are exploited.

Most severe open issueCVSS 9.8CVE-2025-32927

WP FoodBakery <= 3.3 - Unauthenticated PHP Object Injection

Read the full analysis

Vulnerability Records

10 records
2026-07-21 15:42CVE-2026-15802
8.1
High
Rafie MuhammadNo
2025-04-21 00:00CVE-2025-32927
9.8
Critical
BondsNo
2025-03-18 00:00CVE-2024-13933
8.8
High
Lucio SáNo
2025-03-18 00:00CVE-2024-12920
8.8
High
Lucio SáYes
2025-02-10 00:00CVE-2024-13011
9.8
Critical
István MártonYes
2025-02-10 00:00CVE-2025-0180
9.8
Critical
TonnYes
2025-02-10 00:00CVE-2025-0181
9.8
Critical
TonnNo
2025-02-10 00:00CVE-2024-13010
6.1
Medium
István MártonNo
2021-06-14 00:00CVE-2021-24389
6.1
Medium
Truoc PhanYes
2020-07-24 00:00N/A
6.1
Medium
R3N0Yes
Showing 1–10 of 10 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C