CVE-2026-86603
WP Recipe Maker < 10.8.2 - Subscriber+ Non-Public List Title Disclosure via wprm_search_lists
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.
| Vendor | unknown |
| Product | wp recipe maker |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp recipe maker
Be the first to know when new unknown vulnerabilities affecting unknown wp recipe maker are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WP Recipe Maker
0 < 10.8.2
References
Credits
Abdullah Kareem WPScan