Executive brief
The WP Recipe Maker WordPress plugin contains a flaw in its REST API that allows attackers to write unlimited data to user accounts without needing to log in. An attacker can exploit this to corrupt user profiles, including administrator accounts, causing them to become inaccessible and triggering a denial of service for those users.
Technical details
The vulnerable REST route lacks both authorization checks and input validation, permitting unauthenticated attackers to insert unbounded metadata into any user's profile. This is a network-based attack requiring no authentication or user interaction; exploitation results in denial of service by rendering target accounts unusable, including privileged administrative accounts.
Affected products
- WP Recipe Maker WP Recipe Maker 9.8.0 through 10.8.1
Timeline
- 2026-09-21: disclosed
- 2026-09-23: patched: Fixed in version 10.8.2