PT-2026-97180 · WordPress · Wp Recipe Maker
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
WP Recipe Maker versions prior to 10.8.2
Description
An authorization check is missing in a REST route, and the route does not restrict the data it stores. This allows unauthenticated users to write unlimited data into the metadata of any user, which can permanently prevent that account, including administrator accounts, from loading.
Recommendations
Update WP Recipe Maker to version 10.8.2 or later.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Recipe Maker