Junglewise Threat Intelligence

CVE-2026-89274: WP Recipe Maker arbitrary shortcode execution

CVE-2026-89274 · Severity: critical · CVSS 9.1 · Published 2026-09-19

Technologies: WP Recipe Maker. Vendors: WP Recipe Maker.

Executive brief

The WP Recipe Maker plugin for WordPress allows unauthenticated attackers to execute arbitrary shortcodes on recipe pages by injecting shortcode tokens into approved comments. When the plugin renders recipe metadata, it executes these shortcodes before sanitizing the output, causing sensitive data—such as private post content or attachment information—to be embedded and exposed to all visitors in the page's structured metadata.

Technical details

The vulnerability exists in `WPRM_Metadata::sanitize_metadata()`, which recursively calls `do_shortcode()` on recipe metadata fields including `reviewBody` (populated from approved comment content) without pre-sanitization. Unauthenticated attackers can inject shortcode tokens into comments; upon moderation approval, the shortcodes execute server-side during page rendering, and their output is exposed in JSON-LD metadata. Post-execution sanitization via `wp_strip_all_tags()` and `strip_shortcodes()` provides no protection since code execution has already occurred.

Affected products

  • WP Recipe Maker WP Recipe Maker up to and including 10.8.1

Timeline

  • 2026-09-19: disclosed

References

Related threats