Known Vulnerabilities for WP Recipe Maker by Unknown
Listed below are 8 of the newest known vulnerabilities associated with "WP Recipe Maker" by "Unknown".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-90884 json | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all versio... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-89274 json | The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including,... | Not Provided | 2026-09-19 | 2026-09-19 |
| CVE-2026-86608 json | The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does ... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-86603 json | The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-86602 json | The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-86601 json | The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while ... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-75905 json | The WP Recipe Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.8.0. ... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-7877 json | The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-call-to-... | Not Provided | 2026-09-01 | 2026-09-01 |