CVE-2026-86602
WP Recipe Maker 10.3.0 - 10.8.1 - Subscriber+ Draft and Private Recipe Content Disclosure via wprm_shortcode_preview
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes.
| Vendor | unknown |
| Product | wp recipe maker |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp recipe maker
Be the first to know when new unknown vulnerabilities affecting unknown wp recipe maker are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WP Recipe Maker
10.3.0 < 10.8.2
References
Credits
Abdullah Kareem WPScan