WordPress Plugin Vulnerabilities

WP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likes

Description

The plugin does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to modify limited post metadata (a like counter and an associated identifier list) on arbitrary posts, including inflating the counter and growing the stored metadata without bound.

Proof of Concept

Affects Plugins

Fixed in 1.10.2

References

Classification

Miscellaneous

Original Researcher
Pedro Pinho
Submitter
Pedro Pinho
Verified
Yes

Timeline

Publicly Published
2026-07-13 (about 18 days ago)
Added
2026-07-13 (about 17 days ago)
Last Updated
2026-07-13 (about 17 days ago)

Other