Extension WordPress
Vulnérabilités WP Recipe Maker
Cette page rassemble les failles publiées pour WP Recipe Maker, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Recipe Maker
20 fiches
WP Recipe Maker <= 10.3.2 – Insecure Direct Object Reference to Unauthenticated Arbitrary Post Metadata Modification via 'recipeId' Parameter
The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, and including, 10.3.2. This is due to the /wp-json/wp-recipe-maker/v1/integrations/instacart REST API endpoint's permission_callback being set to __return_true and…
*-10.3.2
10.3.3
26/02/2026
WP Recipe Maker <= 10.6.0 – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure
The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ajax_search_recipes' and 'ajax_get_recipe' functions in all versions up to, and including, 10.6.0 This makes it possible…
*-10.6.0
10.6.1
24/02/2026
Recipe Maker <= 10.2.4 – Missing Authorization
The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 10.2.4. This makes it possible for authenticated attackers, with Subscriber-level…
*-10.2.4
10.3.0
28/01/2026
WP Recipe Maker <= 10.2.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 10.2.3 due to insufficient input sanitization and output escaping on user-supplied attributes in the…
*-10.2.3
10.2.4
16/12/2025
WP Recipe Maker <= 10.2.2 – Insecure Direct Object Reference to Sensitive Information Exposure
The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2 via the api_get_post_summary function due to insufficient restrictions on which posts can be retrieved. This makes it possible for…
*-10.2.2
10.2.3
11/12/2025
WP Recipe Maker < 10.1.0 – Unauthenticated Arbitrary Shortcode Execution
The The WP Recipe Maker plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to 10.1.0 (exclusive). This is due to the software allowing users to execute an action that does not properly validate…
[*, 10.1.0)
10.1.0
26/09/2025
WP Recipe Maker <= 9.8.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Roundup Recipe Name field in all versions up to, and including, 9.8.0 due to insufficient input sanitization and output escaping. This makes it…
*-9.8.0
9.8.1
12/03/2025
WP Recipe Maker <= 9.6.1 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'tooltip'
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip’ parameter in all versions up to, and including, 9.6.1 due to insufficient input sanitization and output escaping. This makes it possible for…
*-9.6.1
9.7.0
23/10/2024
WP Recipe Maker <= 9.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'group_tag'
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [wprm-recipe-instructions] and [wprm-recipe-ingredients] shortcodes in all versions up to, and including, 9.1.0 due to insufficient restrictions on the 'group_tag' attribute . This…
*-9.1.0
9.1.1
18/06/2024
WP Recipe Maker <= 9.3.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via wprm-recipe-roundup-item Shortcode
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wprm-recipe-roundup-item shortcode in all versions up to, and including, 9.3.1 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-9.3.1
9.4.0
01/05/2024
WP Recipe Maker <= 9.2.1 – Authenticated Stored Cross-Site Scripting via Video Embed
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video Embed parameter in all versions up to, and including, 9.2.1 due to insufficient input sanitization and output escaping. This makes it possible…
*-9.2.1
9.3.0
14/03/2024
WP Recipe Maker <= 9.1.2 – Missing Authorization to Authenticated (Subscriber+) SQL Injecton
The WP Recipe Maker plugin for WordPress is vulnerable to SQL Injection via the 'recipes' parameter in all versions up to, and including, 9.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-9.1.2
9.2.0
07/02/2024
WP Recipe Maker <= 9.1.0 – Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This…
*-9.1.0
9.1.1
17/01/2024
WP Recipe Maker <= 9.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag'
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute in the wprm-recipe-name, wprm-recipe-date, and wprm-recipe-counter shortcodes in all versions up to, and including, 9.1.0. This makes it…
*-9.1.0
9.1.1
17/01/2024
WP Recipe Maker <= 9.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Recipe Notes
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Notes in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-9.1.0
9.1.1
17/01/2024
WP Recipe Maker <= 9.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via icon_color
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-recipe-text-share' shortcode in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-9.1.0
9.1.1
17/01/2024
WP Recipe Maker <= 9.1.0 – Directory Traversal
The WP Recipe Maker plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 9.1.0 via the 'icon' attribute used in Shortcodes. This makes it possible for authenticated attackers, with contributor-level access and…
*-9.1.0
9.1.1
17/01/2024
WP Recipe Maker <= 9.1.0 – Reflected Cross-Site Scripting via Referer
The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping. This makes it possible for…
*-9.1.0
9.1.1
17/01/2024
WP Recipe Maker <= 9.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via header_tag
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 due to unrestricted use of the 'header_tag' attribute. This makes it possible for…
*-9.1.0
9.1.1
17/01/2024
WP Recipe Maker <= 8.6.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 8.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-8.6.0
8.6.1
19/12/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.