CVE-2026-14305
WP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likes
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to modify limited post metadata (a like counter and an associated identifier list) on arbitrary posts, including inflating the counter and growing the stored metadata without bound.
| Vendor | unknown |
| Product | wp delicious |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp delicious
Be the first to know when new medium vulnerabilities affecting unknown wp delicious are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WP Delicious
0 < 1.10.2
References
Credits
Pedro Pinho WPScan