WordPress Plugin Vulnerabilities

WP Recipe Maker < 10.8.2 - Unauthenticated Arbitrary Shortcode Execution via Comment Content

Description

The plugin does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing unauthenticated users to have arbitrary shortcodes executed server side and to read the content of unpublished recipes.

Proof of Concept

Affects Plugins

Fixed in 10.8.2

References

Classification

Type
INJECTION
OWASP top 10

Miscellaneous

Original Researcher
Jakub Herman
Submitter
Jakub Herman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-21 (about 2 days ago)
Added
2026-09-21 (about 1 day ago)
Last Updated
2026-09-21 (about 1 day ago)

Other