First published: Tue Apr 09 2024(Updated: )
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video Embed parameter in all versions up to, and including, 9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to the recipe dashboard (which is administrator-only by default but can be assigned to arbitrary capabilities), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Recipe Maker | <=9.2.1 | |
<9.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1571 has a severity rating that indicates it could allow attackers to execute stored cross-site scripting attacks.
To fix CVE-2024-1571, update the WP Recipe Maker plugin to version 9.3.0 or later to ensure proper input sanitization.
CVE-2024-1571 affects all versions of the WP Recipe Maker plugin up to and including version 9.2.1.
CVE-2024-1571 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
Yes, authenticated attackers with access to the recipe data can exploit CVE-2024-1571 due to insufficient sanitization.