← WordPress Vulnerabilities
WordPress security by component

WP Recipe Maker

WP Recipe Maker is a WordPress component with 20 published CVE records in this archive. The latest tracked vulnerability was published Feb 27, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: wp-recipe-maker

CVE-2026-1558: WP Recipe Maker: A security weakness

WP Recipe Maker is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedFeb 27, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 27, 2026 CVE-2026-1558
WP Recipe Maker: A security weakness
WP Recipe Maker is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Feb 25, 2026 CVE-2025-14742
WP Recipe Maker: A security weakness
WP Recipe Maker is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jan 22, 2026 CVE-2026-24357
WP Recipe Maker: A security weakness
WP Recipe Maker is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jan 16, 2026 CVE-2025-15527
WP Recipe Maker: A security weakness
WP Recipe Maker is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Dec 17, 2025 CVE-2025-14385
WP Recipe Maker: Cross-site scripting
WP Recipe Maker is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Oct 27, 2025 CVE-2025-62897
WP Recipe Maker: Cross-site scripting
WP Recipe Maker is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.3
NVDPending
Mar 13, 2025 CVE-2025-1503
WP Recipe Maker: Cross-site scripting
WP Recipe Maker is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Oct 24, 2024 CVE-2024-9650
WP Recipe Maker: Cross-site scripting
WP Recipe Maker is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jun 19, 2024 CVE-2024-0383
WP Recipe Maker: Cross-site scripting
WP Recipe Maker is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-3490
WP Recipe Maker: Cross-site scripting
WP Recipe Maker is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 09, 2024 CVE-2024-1571
WP Recipe Maker: Cross-site scripting
WP Recipe Maker is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Feb 29, 2024 CVE-2024-1206
WP Recipe Maker: SQL injection
WP Recipe Maker is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVDPending
Feb 05, 2024 CVE-2024-0384
WP Recipe Maker: Cross-site scripting
WP Recipe Maker is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 05, 2024 CVE-2024-0382
WP Recipe Maker: Cross-site scripting
WP Recipe Maker is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 05, 2024 CVE-2024-0380
WP Recipe Maker: Cross-site scripting
WP Recipe Maker is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD4.3
Feb 05, 2024 CVE-2024-0255
WP Recipe Maker: Cross-site scripting
WP Recipe Maker is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 18, 2024 CVE-2024-0381
WP Recipe Maker: Cross-site scripting
WP Recipe Maker is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 18, 2024 CVE-2023-6970
WP Recipe Maker: Cross-site scripting
WP Recipe Maker is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jan 18, 2024 CVE-2023-6958
WP Recipe Maker: Cross-site scripting
WP Recipe Maker is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 09, 2023 CVE-2022-4468
WP Recipe Maker: Cross-site scripting
WP Recipe Maker is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4