medium · CVSS v3 4.3 · EPSS 0.0019
CVE-2026-86603
WP Recipe Maker plugin versions prior to 10.8.2 lack an authorization check on an AJAX endpoint, enabling any logged-in user to view unpubli
Overview
WP Recipe Maker plugin versions prior to 10.8.2 lack an authorization check on an AJAX endpoint, enabling any logged-in user to view unpublished recipe list IDs and titles. This flaw can expose sensitive content and user data. It affects sites running the vulnerable plugin.
Description
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.
Impact
Confidentiality: Unpublished recipe lists and associated user IDs can be exposed to any authenticated user. Integrity: The data remains unmodified but is disclosed. Availability: No direct impact. Defenders should monitor for unauthorized data access and restrict role permissions.
Remediation
Upgrade WP Recipe Maker to version 10.8.2 or later. If upgrade not possible, disable the vulnerable AJAX endpoint or restrict it to administrators via role checks. Verify that the plugin’s role capability is set to 'manage_options' or higher. Monitor user activity logs for suspicious list access.
Risk context
Severity is medium (CVSS 4.3) and EPSS is 0.0019, indicating low likelihood of exploitation but still relevant for sites with sensitive unpublished content. Defenders should act promptly to mitigate potential data leakage.
Affected products
- WP Recipe Maker
Scores
- Severity
- medium
- CVSS v2
- 4
- CVSS v3
- 4.3
- CVSS v4
- —
- EPSS
- 0.0019