{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/chimpstudio/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-15802"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Foodbakery \u003c= 4.9"],"_cs_severities":["high"],"_cs_tags":["wordpress","plugin","arbitrary-file-deletion","rce","cve"],"_cs_type":"advisory","_cs_vendors":["Chimpstudio"],"content_html":"\u003cp\u003eOn July 22, 2026, the National Vulnerability Database (NVD) disclosed CVE-2026-15802, an arbitrary file deletion vulnerability affecting the WP Foodbakery plugin for WordPress, versions up to and including 4.9. This vulnerability stems from insufficient file path validation within the \u003ccode\u003edelete_locations_backup_file_callback\u003c/code\u003e function, allowing authenticated attackers with subscriber-level access or higher to delete arbitrary files on the server. The exploitation of this flaw can lead to severe consequences, including remote code execution (RCE) if critical files, such as \u003ccode\u003ewp-config.php\u003c/code\u003e, are deleted. This vulnerability presents a high risk to WordPress installations utilizing the affected plugin, as it could result in full site compromise, data loss, or disruption of service.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains authenticated access to a WordPress site, requiring at least subscriber-level permissions.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies the presence and version of the vulnerable WP Foodbakery plugin (versions \u0026lt;= 4.9).\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP request targeting the \u003ccode\u003edelete_locations_backup_file_callback\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eThe request includes a path traversal sequence (e.g., \u003ccode\u003e../\u003c/code\u003e, \u003ccode\u003e..%2f\u003c/code\u003e) within the file path parameter.\u003c/li\u003e\n\u003cli\u003eDue to insufficient file path validation, the plugin processes the manipulated path.\u003c/li\u003e\n\u003cli\u003eThe plugin's vulnerable function deletes an arbitrary file on the server specified by the attacker's crafted path.\u003c/li\u003e\n\u003cli\u003eBy deleting a critical file like \u003ccode\u003ewp-config.php\u003c/code\u003e, the attacker forces a WordPress reinstallation or gains RCE through subsequent site misconfiguration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-15802 allows authenticated attackers to delete arbitrary files on the affected WordPress server. This can lead to denial of service due to critical file removal or, more severely, remote code execution. If the \u003ccode\u003ewp-config.php\u003c/code\u003e file is deleted, it can force a WordPress reinstallation, potentially enabling an attacker to reconfigure the site with malicious settings or gain full control. The direct impact includes data loss, website defacement, and unauthorized access to the underlying server environment, affecting the confidentiality, integrity, and availability of the web application and its data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-15802 immediately by updating the WP Foodbakery plugin to a version greater than 4.9 to address the arbitrary file deletion vulnerability.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to your SIEM solution to detect suspicious web server requests indicative of CVE-2026-15802 exploitation attempts.\u003c/li\u003e\n\u003cli\u003eConfigure your Web Application Firewall (WAF) to block HTTP requests containing path traversal sequences (e.g., \u003ccode\u003e../\u003c/code\u003e, \u003ccode\u003e..%2f\u003c/code\u003e, \u003ccode\u003e%2e%2e%2f\u003c/code\u003e) targeting known WordPress AJAX endpoints or file deletion functions, particularly those related to the \u003ccode\u003edelete_locations_backup_file_callback\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for any suspicious activity related to \u003ccode\u003e/wp-admin/admin-ajax.php\u003c/code\u003e and the \u003ccode\u003edelete_locations_backup_file_callback\u003c/code\u003e action parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T05:18:38Z","date_published":"2026-07-22T05:18:38Z","id":"https://feed.craftedsignal.io/briefs/2026-07-wp-foodbakery-file-deletion/","summary":"The WP Foodbakery plugin for WordPress, specifically versions up to and including 4.9, is vulnerable to arbitrary file deletion (CVE-2026-15802) due to insufficient file path validation, allowing authenticated attackers with subscriber-level access to delete critical server files, potentially leading to remote code execution.","title":"WP Foodbakery Plugin Arbitrary File Deletion Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-wp-foodbakery-file-deletion/"}],"language":"en","title":"CraftedSignal Threat Feed - Chimpstudio","version":"https://jsonfeed.org/version/1.1"}