← WordPress Vulnerabilities
WordPress security by component

WP Recipe Maker Premium

WP Recipe Maker Premium (wp-recipe-maker-premium) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 01, 2026; the highest published CVSS base score is 6.4.

Plugin slug: wp-recipe-maker-premium

CVE-2026-7877: WP Recipe Maker Premium call-to-action shortcodes permit stored cross-site scripting

WP Recipe Maker Premium through 10.5.0 insufficiently sanitizes and escapes user-controlled attributes of the wprm-call-to-action shortcode. A Contributor or higher can store script that executes in the site's origin when another user views the affected page.

PublishedSep 01, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for wp-recipe-maker-premium
Safe version
Sep 01, 2026 CVE-2026-7877
WP Recipe Maker Premium call-to-action shortcodes permit stored cross-site scripting
WP Recipe Maker Premium through 10.5.0 insufficiently sanitizes and escapes user-controlled attributes of the wprm-call-to-action shortcode. A Contributor or higher can store script that executes in the site's origin when another user views the affected page.
See mitigation notes
CVE6.4
NVDPending