CVE-2026-89274
9.1 CRITICALPublished 2026-09-19 · Updated 2026-09-21
AI risk analysis
- Summary
- The WP Recipe Maker plugin allows unauthenticated attackers to execute arbitrary shortcodes server-side, leading to potential disclosure of sensitive data.
- Exploitability
- Exploitation requires an attacker to post a comment that is approved, making it moderately hard to exploit.
- Blast radius
- If exploited, the vulnerability could disclose sensitive data to all visitors, impacting user privacy and site integrity.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Disable the WP Recipe Maker plugin until a patch is available, or upgrade to version 10.8.2 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the `reviewBody` field, which is populated verbatim from the `comment_content` of approved `wprm-comment-rating` comments — without sanitizing or stripping shortcode tokens before execution; the subsequent `wp_strip_all_tags()` and `strip_shortcodes()` calls operate only on the output string after execution has already fully occurred, providing no protection against server-side shortcode invocation. This makes it possible for unauthenticated attackers to execute arbitrary registered WordPress shortcodes server-side on every recipe page render, causing shortcode output — such as attachment captions, private post fields, or other data exposed by installed shortcodes — to be embedded in the page's JSON-LD `reviewBody` metadata and disclosed to all visitors who load the recipe page. Successful exploitation requires the attacker's rated comment to pass the site's comment approval threshold, either via auto-approval or moderator action, before the injected shortcode begins executing on page loads.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-94
All references
- https://plugins.trac.wordpress.org/browser/wp-recipe-maker/tags/10.8.1/includes/public/class-wprm-metadata.php#L1028
- https://plugins.trac.wordpress.org/browser/wp-recipe-maker/tags/10.8.1/includes/public/class-wprm-metadata.php#L181
- https://plugins.trac.wordpress.org/browser/wp-recipe-maker/tags/10.8.1/includes/public/class-wprm-metadata.php#L553
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3699793%40wp-recipe-maker&new=3699793%40wp-recipe-maker
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d6ad49ff-85eb-4d05-ba23-51d89695add3?source=cve
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-70553PoC
- CRITICALCVE-2026-75031PoC
- CRITICALCVE-2026-90817
- CRITICALCVE-2023-54399
- CRITICALCVE-2026-12342
- CRITICALCVE-2026-13249
- CRITICALCVE-2026-28324
- HIGHCVE-2026-28325
Related by shared AI tags and CWE weakness class. Browse the full archive.