Extension WordPress

Vulnérabilités WP Recipe Maker

Cette page rassemble les failles publiées pour WP Recipe Maker, leurs plages de versions affectées et les correctifs signalés dans la base locale.

20Vulnérabilités
0Critiques
20Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WP Recipe Maker

20 fiches

CVE-2026-1558 Moyenne · 5,3
WP Recipe Maker

WP Recipe Maker <= 10.3.2 – Insecure Direct Object Reference to Unauthenticated Arbitrary Post Metadata Modification via 'recipeId' Parameter

The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, and including, 10.3.2. This is due to the /wp-json/wp-recipe-maker/v1/integrations/instacart REST API endpoint's permission_callback being set to __return_true and…

Versions affectées

*-10.3.2

Correctif

10.3.3

Publication

26/02/2026

CVE-2025-14742 Moyenne · 4,3
WP Recipe Maker

WP Recipe Maker <= 10.6.0 – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure

The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ajax_search_recipes' and 'ajax_get_recipe' functions in all versions up to, and including, 10.6.0 This makes it possible…

Versions affectées

*-10.6.0

Correctif

10.6.1

Publication

24/02/2026

CVE-2024-9650 Moyenne · 6,5
WP Recipe Maker

WP Recipe Maker <= 9.6.1 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'tooltip'

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip’ parameter in all versions up to, and including, 9.6.1 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-9.6.1

Correctif

9.7.0

Publication

23/10/2024

CVE-2024-0383 Moyenne · 6,4
WP Recipe Maker

WP Recipe Maker <= 9.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'group_tag'

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [wprm-recipe-instructions] and [wprm-recipe-ingredients] shortcodes in all versions up to, and including, 9.1.0 due to insufficient restrictions on the 'group_tag' attribute . This…

Versions affectées

*-9.1.0

Correctif

9.1.1

Publication

18/06/2024

CVE-2024-3490 Moyenne · 6,4
WP Recipe Maker

WP Recipe Maker <= 9.3.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via wprm-recipe-roundup-item Shortcode

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wprm-recipe-roundup-item shortcode in all versions up to, and including, 9.3.1 due to insufficient input sanitization and output escaping on user supplied attributes.…

Versions affectées

*-9.3.1

Correctif

9.4.0

Publication

01/05/2024

CVE-2024-0255 Moyenne · 6,4
WP Recipe Maker

WP Recipe Maker <= 9.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via icon_color

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-recipe-text-share' shortcode in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping on user supplied attributes.…

Versions affectées

*-9.1.0

Correctif

9.1.1

Publication

17/01/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités