PT-2026-60438 · Wpdelicious+1 · Wp Delicious – Recipe Plugin For Food Bloggers+1

·

CVE-2026-15099

·

Published

2026-07-15

·

Updated

2026-07-16

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Delicious Recipes versions prior to 1.10.3
Description Stored Cross-Site Scripting occurs via the 'steps' block attribute. The issue stems from insufficient input sanitization and output escaping within the wrap direction text() function. Specifically, the function interpolates the user-supplied href value from nested link nodes ($node['props']['href']) directly into an anchor tag using sprintf() without applying esc url() or performing URL scheme validation. Authenticated attackers with Contributor-level access or higher can inject arbitrary web scripts, such as javascript: URIs, into pages. These scripts execute when a user, such as an editor or administrator, previews the pending post and clicks the malicious link.
Recommendations Update Delicious Recipes to version 1.10.3 or later. As a temporary mitigation, restrict users with Contributor-level access from editing the 'steps' block attribute.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15099

Affected Products

Wp Delicious – Recipe Plugin For Food Bloggers
Delicious Recipes