PT-2026-99247 · WordPress · Wp Delicious

·

CVE-2026-92411

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Delicious WordPress plugin versions prior to 1.10.8
Description Insufficient validation and escaping of HTML tag names derived from user-supplied recipe block data allows users with the Contributor role and above to inject arbitrary HTML tags, including script tags. These tags execute when the recipe page is viewed on the front end.
Recommendations Update WP Delicious WordPress plugin to version 1.10.8 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92411

Affected Products

Wp Delicious