Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

WP Recipe Maker — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in WP Recipe Maker, with AI-generated Chinese analysis, references, and POCs.

This page documents security weaknesses associated with WP Recipe Maker, a popular WordPress plugin designed for creating and managing recipes on websites. It aggregates information regarding various vulnerability types, including cross-site scripting, SQL injection, and improper access control flaws that may affect the plugin's functionality or data integrity. The content covers reported vulnerabilities from initial discovery through recent patch releases, ensuring a comprehensive historical view of the product's security landscape. Visitors to this resource can track advisory updates issued by the vendor to stay informed about critical fixes and security best practices. Users can also gain a deeper understanding of specific weakness classes commonly found in this type of software, helping to identify potential risks in their own implementations. Additionally, the page serves as a reference for looking up the complete vulnerability history of WP Recipe Maker, allowing developers and site administrators to assess the impact of past issues and verify that appropriate mitigations have been applied. This aggregated view supports better decision-making regarding plugin updates and security configurations, fostering a more secure environment for WordPress users who rely on this tool for recipe management. By centralizing these details, the page aims to simplify the process of monitoring and responding to security threats without requiring external searches or fragmented data sources.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-1558 WP Recipe Maker <= 10.3.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Metadata Modification via 'recipeId' Parameter CWE-639 5.3 Medium2026-02-27
CVE-2025-14742 WP Recipe Maker <= 10.2.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure CWE-639 4.3 Medium2026-02-25
CVE-2026-24357 WordPress WP Recipe Maker plugin <= 10.2.4 - Broken Access Control vulnerability CWE-862 4.3 Medium2026-01-22
CVE-2025-15527 WP Recipe Maker <= 10.2.2 - Insecure Direct Object Reference to Sensitive Information Exposure CWE-200 4.3 Medium2026-01-16
CVE-2025-14385 WP Recipe Maker <= 10.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium2025-12-17
CVE-2025-62897 WordPress WP Recipe Maker plugin < 10.1.0 - Content Injection vulnerability CWE-80 5.3 Medium2025-10-27
CVE-2025-1503 WP Recipe Maker <= 9.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2025-03-13
CVE-2024-9650 WP Recipe Maker <= 9.6.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'tooltip' CWE-79 6.5 Medium2024-10-24
CVE-2024-0383 WP Recipe Maker <= 9.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'group_tag' CWE-79 6.4 Medium2024-06-19
CVE-2024-3490 WP Recipe Maker <= 9.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wprm-recipe-roundup-item Shortcode CWE-79 6.4 Medium2024-05-02
CVE-2024-1571 WP Recipe Maker <= 9.2.1 - Authenticated Stored Cross-Site Scripting via Video Embed CWE-79 4.4 Medium2024-04-09
CVE-2024-1206 WP Recipe Maker <= 9.1.2 - Missing Authorization to Authenticated (Subscriber+) SQL Injecton CWE-89 8.8 High2024-02-20
CVE-2024-0384 WP Recipe Maker <= 9.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Recipe Notes CWE-79 6.4 Medium2024-02-05
CVE-2024-0255 WP Recipe Maker <= 9.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via icon_color CWE-79 6.4 Medium2024-02-05
CVE-2024-0380 WP Recipe Maker <= 9.1.0 - Directory Traversal CWE-22 5.4 Medium2024-02-05
CVE-2024-0382 WP Recipe Maker <= 9.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via header_tag CWE-79 6.4 Medium2024-02-05
CVE-2024-0381 WP Recipe Maker <= 9.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' CWE-79 6.4 Medium2024-01-18
CVE-2023-6958 WP Recipe Maker <= 9.1.0 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium2024-01-18
CVE-2023-6970 WP Recipe Maker <= 9.1.0 - Reflected Cross-Site Scripting via Referer CWE-79 6.1 Medium2024-01-18
CVE-2022-4468 WP Recipe Maker < 8.6.1 - Contributor+ Stored XSS 5.4 -2023-01-09

All 20 known CVE vulnerabilities affecting WP Recipe Maker with full Chinese analysis, references, and POCs where available.