CVE-2026-86601: WP Recipe Maker < 10.8.2 - Unauthenticated Arbitrary Shortcode Execution via Comment Content
The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing unauthenticated users to have arbitrary shortcodes executed server side and to read the content of unpublished recipes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WP Recipe Makerto a version that resolves this vulnerability.Fixed in 10.8.2
Event History
Frequently Asked Questions
Who is exposed to this issue?
Sites using WP Recipe Maker versions earlier than 10.8.2 are affected. An attacker does not need an account or user interaction to exploit it.
What can an attacker gain through exploitation?
An attacker can cause arbitrary shortcodes to be executed server-side during structured metadata generation and can read the contents of unpublished recipes.
How can I tell whether my site may be affected?
Check whether WP Recipe Maker is installed and whether its version is earlier than 10.8.2. The issue is relevant where comment content can be processed while the plugin builds page structured metadata.