Junglewise Threat Intelligence

CVE-2026-86603: WP Recipe Maker information disclosure in AJAX action

CVE-2026-86603 · Severity: medium · CVSS 4.3 · Published 2026-09-23

Technologies: WP Recipe Maker. Vendors: WP Recipe Maker.

Executive brief

The WP Recipe Maker WordPress plugin before version 10.8.2 fails to properly verify permissions in one of its AJAX functions, allowing any logged-in user to view private list titles and IDs belonging to other users. This information disclosure could help attackers identify and target other users' content.

Technical details

The vulnerability is an authorization bypass (CWE-200) in an AJAX action handler that lacks proper capability checks. Any authenticated user (including those with subscriber-level permissions) can call the affected AJAX function to retrieve sensitive metadata (IDs and titles) from unpublished lists owned by other users. The issue is resolved in version 10.8.2.

Affected products

  • WP Recipe Maker WP Recipe Maker before 10.8.2

Timeline

  • 2026-09-21: disclosed

References

Related threats