CVE-2026-3011: Recipe Card Blocks Lite <= 3.4.13 - Authenticated (Author+) Stored Cross-Site Scripting via 'summary' and 'notes'
The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions up to, and including, 3.4.13. This is due to the 'WPZOOMHelpers::deserializeblockattributes' method converting unicode-encoded sequences back into HTML characters after sanitization has already been applied. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that execute whenever a user accesses the published post or the print view of an injected recipe.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Recipe Card Blocks Litefrom your environment.Uninstall the Recipe Card Blocks Lite plugin from affected WordPress installations if it is not required.
- Compensating control
Restrict Author-level (and lower) users from adding, editing, or publishing posts containing recipe blocks; limit plugin usage to trusted administrator accounts until a patched version is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3011?
CVE-2026-3011 has a medium severity rating of 6.4.
How do I fix CVE-2026-3011?
To fix CVE-2026-3011, update the Recipe Card Blocks Lite plugin to version 3.4.14 or higher.
What are the vulnerabilities of CVE-2026-3011?
CVE-2026-3011 is vulnerable to stored cross-site scripting via the 'summary' and 'notes' attributes.
Who is affected by CVE-2026-3011?
CVE-2026-3011 affects anyone using Recipe Card Blocks Lite versions up to and including 3.4.13.
What type of vulnerability is CVE-2026-3011?
CVE-2026-3011 is classified as a stored cross-site scripting (XSS) vulnerability.