WordPress · Wp Recipe Maker · CVE-2026-86608
**Name of the Vulnerable Software and Affected Versions**
WP Recipe Maker versions prior to 10.8.2
**Description**
An authorization check is missing in a REST route, and the route does not restrict the data it stores. This allows unauthenticated users to write unlimited data into the metadata of any user, which can permanently prevent that account, including administrator accounts, from loading.
**Recommendations**
Update WP Recipe Maker to version 10.8.2 or later.