Junglewise Threat Intelligence

CVE-2026-57663: Igor Benic Recipe Maker For Your Food Blog SQL injection

CVE-2026-57663 · Severity: high · CVSS 8.5 · Published 2026-06-26

Executive brief

A vulnerability in the Recipe Maker For Your Food Blog plugin for WordPress allows users with 'Contributor' level access to perform unauthorized database operations. This could lead to the theft of sensitive information or disruption of the website's database services. The issue affects versions up to 8.2.7 and has been addressed in version 8.2.8.

Technical details

A SQL injection vulnerability exists in the 'Recipe Maker For Your Food Blog from Zip Recipes' WordPress plugin due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is present in versions up to and including 8.2.7. An attacker with Contributor-level privileges can exploit this over the network without user interaction to execute arbitrary SQL queries. This can result in unauthorized data retrieval from the database or limited impact on database availability. The vulnerability is patched in version 8.2.8.

Affected products

  • Igor Benic Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7

Timeline

  • 2026-05-08: disclosed: Reported by ParkHyunWoo
  • 2026-06-26: advisory: Published by Patchstack
  • 2026-06-26: patched: Fixed in version 8.2.8

References