Executive brief
The Delicious Recipes plugin for WordPress, used by food bloggers to display recipe cards, contains a security flaw that allows users with contributor-level access to inject malicious scripts into website pages. These scripts can execute in the browser of other users, such as site administrators, when they view or preview the affected recipe posts. This could lead to unauthorized actions being performed on behalf of the administrator or the theft of sensitive session information.
Technical details
The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the wrap_direction_text() function. Specifically, the function interpolates user-supplied href values from nested link nodes directly into an anchor tag via sprintf() without using esc_url() or validating the URL scheme. This allows authenticated attackers with Contributor-level permissions or higher to inject arbitrary web scripts, such as javascript: URIs, into the 'steps' block attribute. These scripts execute when a user, such as an editor or administrator, interacts with the malicious link while previewing or viewing the post. The issue is fixed in versions following 1.10.2.
Affected products
- wpdelicious Delicious Recipes (WP Delicious) up to, and including, 1.10.2
Timeline
- 2026-07-16: disclosed
- 2026-07-16: advisory
References
- https://plugins.trac.wordpress.org/browser/delicious-recipes/tags/1.10.2/src/blocks/dynamic-blocks/class-delicious-dynamic-recipe-card.php
- https://plugins.trac.wordpress.org/browser/delicious-recipes/tags/1.10.2/src/blocks/dynamic-blocks/class-delicious-dynamic-recipe-card.php
- https://plugins.trac.wordpress.org/browser/delicious-recipes/tags/1.10.2/src/blocks/dynamic-blocks/class-delicious-dynamic-recipe-card.php
- https://plugins.trac.wordpress.org/changeset/3605415/delicious-recipes
- https://www.wordfence.com/threat-intel/vulnerabilities/id/4a89c812-a643-47c0-bd33-cfb2389a7646?source=cve