Junglewise Threat Intelligence

CVE-2026-86601: WP Recipe Maker arbitrary shortcode execution in comments

CVE-2026-86601 · Severity: medium · CVSS 6.5 · Published 2026-09-23

Technologies: WP Recipe Maker.

Executive brief

The WP Recipe Maker WordPress plugin fails to sanitize shortcodes in user comments before processing them to generate page metadata. An unauthenticated attacker can inject arbitrary shortcodes into comments to execute code on the server and access unpublished recipe content, potentially compromising the website and exposing sensitive information.

Technical details

The plugin does not strip shortcodes from comment content during structured metadata generation, allowing arbitrary shortcode injection. An unauthenticated attacker can post a malicious comment containing shortcodes that execute server-side code and disclose unpublished recipe data. The vulnerability affects versions before 10.8.2.

Affected products

  • WP Recipe Maker before 10.8.2

Timeline

  • 2026-09-21: disclosed
  • 2026-09-23: advisory
  • 2026-09-21: patched: Fixed in version 10.8.2

References