๐Ÿ” CVE Alert

CVE-2026-14305

MEDIUM 5.3

WP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likes

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to modify limited post metadata (a like counter and an associated identifier list) on arbitrary posts, including inflating the counter and growing the stored metadata without bound.

Vendor unknown
Product wp delicious
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wp delicious

Be the first to know when new medium vulnerabilities affecting unknown wp delicious are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WP Delicious
0 < 1.10.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/6a2aecc7-3fbb-4d63-b1ac-4f8243ca872b/

Credits

Pedro Pinho WPScan