First published: Tue Feb 11 2025(Updated: )
The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible for unauthenticated attackers to register on the site as an administrator.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Foodbakery | <=3.3 | |
WP Foodbakery | <4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0180 is classified as a high severity vulnerability due to its potential for privilege escalation.
To mitigate CVE-2025-0180, update the WP Foodbakery plugin to version 3.4 or later.
All users of the WP Foodbakery plugin for WordPress up to version 3.3 are affected by CVE-2025-0180.
CVE-2025-0180 is a privilege escalation vulnerability that allows unauthenticated users to register and update user meta.
Yes, CVE-2025-0180 can be exploited remotely by unauthenticated attackers.