Executive brief
The WP Recipe Maker WordPress plugin fails to sanitize shortcodes in user comments before processing them to generate page metadata. An unauthenticated attacker can inject arbitrary shortcodes into comments to execute code on the server and access unpublished recipe content, potentially compromising the website and exposing sensitive information.
Technical details
The plugin does not strip shortcodes from comment content during structured metadata generation, allowing arbitrary shortcode injection. An unauthenticated attacker can post a malicious comment containing shortcodes that execute server-side code and disclose unpublished recipe data. The vulnerability affects versions before 10.8.2.
Affected products
- WP Recipe Maker before 10.8.2
Timeline
- 2026-09-21: disclosed
- 2026-09-23: advisory
- 2026-09-21: patched: Fixed in version 10.8.2