Search
Search Results (4 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-86602 | 1 Wordpress-extensions | 1 Wp Recipe Maker | 2026-09-28 | 4.3 Medium |
| The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes. | ||||
| CVE-2026-86603 | 1 Wordpress-extensions | 1 Wp Recipe Maker | 2026-09-28 | 4.3 Medium |
| The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists. | ||||
| CVE-2026-86608 | 1 Wordpress-extensions | 1 Wp Recipe Maker | 2026-09-28 | 8.2 High |
| The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what that route stores, allowing unauthenticated users to write unlimited data into any user's metadata and to permanently prevent that account, including an administrator's, from loading. | ||||
| CVE-2026-86601 | 1 Wordpress-extensions | 1 Wp Recipe Maker | 2026-09-28 | 6.5 Medium |
| The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing unauthenticated users to have arbitrary shortcodes executed server side and to read the content of unpublished recipes. | ||||
Page 1 of 1.