Junglewise Threat Intelligence

CVE-2026-39528: WP Delicious WordPress plugin broken access control

CVE-2026-39528 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

WP Delicious is a WordPress plugin used to create and manage recipe content on websites. A security flaw in versions 1.9.5 and earlier allows unauthorized individuals to bypass access controls due to incorrectly configured security levels. This could potentially allow an attacker to access information or perform actions that should be restricted to site administrators.

Technical details

The WP Delicious (delicious-recipes) plugin for WordPress suffers from a Missing Authorization (CWE-862) vulnerability. The flaw stems from incorrectly configured access control security levels within the plugin's functional components. An unauthenticated remote attacker can exploit this by sending crafted requests to the affected site, potentially allowing them to execute functions or access data intended for higher-privileged users. The vulnerability is addressed in version 1.9.6.

Affected products

  • WP Delicious WP Delicious (delicious-recipes) <= 1.9.5

Timeline

  • 2026-01-26: disclosed: Reported by researcher hhhai
  • 2026-02-25: advisory: Patchstack published advisory
  • 2026-04-08: advisory: CVE published to NVD
  • 2026-02-25: patched: Fixed in version 1.9.6

References

Related threats