Cooked Pro
Cooked Pro adds recipe publishing, ingredient lists, cooking instructions, recipe indexes, and meal-related content features to WordPress.
Cooked Pro (cooked) is a WordPress plugin with 13 published CVE records in this archive. The latest tracked vulnerability was published Sep 17, 2026; the highest published CVSS base score is 9.8.
cookedCVE-2026-73999: Cooked has contributor-level insecure direct object references
Cooked through 1.16.0 has insecure direct object references requiring Contributor access according to the description. The disclosed class means a supplied object reference is not adequately checked against the caller's authority; the affected object and identifier field are not named. The CNA vector indicates limited integrity and availability impact without victim interaction. The export does not identify an endpoint, action, function or concrete data fields, so a specific exploit sequence cannot be established. The affected-version data marks 1.16.1 unaffected.
| Safe version |
|
||
|---|---|---|---|
| Sep 17, 2026 |
CVE-2026-73999
Cooked has contributor-level insecure direct object references
Cooked through 1.16.0 has insecure direct object references requiring Contributor access according to the description. The disclosed class means a supplied object reference is not adequately checked against the caller's authority; the affected object and identifier field are not named. The CNA vector indicates limited integrity and availability impact without victim interaction. The export does not identify an endpoint, action, function or concrete data fields, so a specific exploit sequence cannot be established. The affected-version data marks 1.16.1 unaffected.
|
1.16.1 |
CVE5.4
NVDPending
|
| Dec 31, 2025 |
CVE-2025-62989
Cooked: Cross-site scripting
Cooked is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Dec 24, 2025 |
CVE-2025-68586
Cooked: A security weakness
Cooked is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Aug 05, 2024 |
CVE-2024-41816
Cooked: Cross-site scripting
Cooked is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jul 18, 2024 |
CVE-2024-39682
Cooked: A security weakness
Cooked is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jul 18, 2024 |
CVE-2024-39681
Cooked: Cross-site request forgery
Cooked is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Jul 18, 2024 |
CVE-2024-39680
Cooked: Cross-site request forgery
Cooked is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Jul 18, 2024 |
CVE-2024-39679
Cooked: Cross-site request forgery
Cooked is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Jul 18, 2024 |
CVE-2024-39678
Cooked: Cross-site request forgery
Cooked is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Jun 13, 2024 |
CVE-2024-37308
Cooked Pro recipe: Cross-site scripting
Cooked Pro recipe is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Oct 02, 2023 |
CVE-2023-44477
Cooked: Cross-site scripting
Cooked is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Dec 12, 2022 |
CVE-2022-3900
Cooked Pro: Code execution
Cooked Pro is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Apr 22, 2021 |
CVE-2021-24233
Cooked Pro: Cross-site scripting
Cooked Pro is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|