CVE-2026-86603: WP Recipe Maker < 10.8.2 - Subscriber+ Non-Public List Title Disclosure via wprm_search_lists
Published Sep 23, 2026
·Updated
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.
Affected Software
1 affected component
Bootstrapped Ventures WP Recipe Maker<10.8.2
Event History
Sep 23, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any authenticated WordPress user can exploit it, including users with the Subscriber role. The affected AJAX action does not enforce an authorization check.
2
What information can be disclosed?
An attacker can retrieve the IDs and titles of unpublished lists belonging to other users. The provided information does not indicate disclosure of list contents or other metadata.
3
Which versions are affected?
WP Recipe Maker versions before 10.8.2 are affected. Updating to version 10.8.2 or later addresses the missing authorization check.