rootpwn

medium · CVSS v3 4.3 · EPSS 0.0019

CVE-2026-86603

WP Recipe Maker plugin versions prior to 10.8.2 lack an authorization check on an AJAX endpoint, enabling any logged-in user to view unpubli

Overview

WP Recipe Maker plugin versions prior to 10.8.2 lack an authorization check on an AJAX endpoint, enabling any logged-in user to view unpublished recipe list IDs and titles. This flaw can expose sensitive content and user data. It affects sites running the vulnerable plugin.

Description

The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.

Impact

Confidentiality: Unpublished recipe lists and associated user IDs can be exposed to any authenticated user. Integrity: The data remains unmodified but is disclosed. Availability: No direct impact. Defenders should monitor for unauthorized data access and restrict role permissions.

Remediation

Upgrade WP Recipe Maker to version 10.8.2 or later. If upgrade not possible, disable the vulnerable AJAX endpoint or restrict it to administrators via role checks. Verify that the plugin’s role capability is set to 'manage_options' or higher. Monitor user activity logs for suspicious list access.

Risk context

Severity is medium (CVSS 4.3) and EPSS is 0.0019, indicating low likelihood of exploitation but still relevant for sites with sensitive unpublished content. Defenders should act promptly to mitigate potential data leakage.

Affected products

  • WP Recipe Maker

Scores

Severity
medium
CVSS v2
4
CVSS v3
4.3
CVSS v4
EPSS
0.0019

wordpress plugin authorization data-exposure wp-recipe-maker medium EPSS

← All CVEs