CVE-2026-86602 PUBLISHED

WP Recipe Maker 10.3.0 - 10.8.1 - Subscriber+ Draft and Private Recipe Content Disclosure via wprm_shortcode_preview

Assigner: WPScan
Reserved: 08.09.2026 Published: 23.09.2026 Updated: 23.09.2026

The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes.

Product Status

Vendor Unknown
Product WP Recipe Maker
Versions Default: unaffected
  • affected from 10.3.0 to 10.8.2 (excl.)

Credits

  • Abdullah Kareem finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE