The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing unauthenticated users to have arbitrary shortcodes executed server side and to read the content of unpublished recipes.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing unauthenticated users to have arbitrary shortcodes executed server side and to read the content of unpublished recipes. | |
| Title | WP Recipe Maker < 10.8.2 - Unauthenticated Arbitrary Shortcode Execution via Comment Content | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T10:50:16.377Z
Reserved: 2026-09-08T08:38:29.882Z
Link: CVE-2026-86601
Updated: 2026-09-23T10:33:33.163Z
Status : Received
Published: 2026-09-23T11:17:13.970
Modified: 2026-09-23T11:17:13.970
Link: CVE-2026-86601
No data.
OpenCVE Enrichment
No data.
Weaknesses