WordPress · Wp Recipe Maker · CVE-2026-90884
**Name of the Vulnerable Software and Affected Versions**
WP Recipe Maker versions prior to 10.8.2
**Description**
Insufficient input sanitization and output escaping allow authenticated attackers with Contributor-level access and above to perform Stored Cross-Site Scripting. This is achieved by injecting arbitrary web scripts via the `notes` parameter in the REST Preview endpoint, which then execute when a user accesses the affected page.
**Recommendations**
Update WP Recipe Maker to version 10.8.2 or later.
As a temporary mitigation, restrict access to the `notes` parameter in the REST Preview endpoint.