CVE-2026-86603 PUBLISHED

WP Recipe Maker < 10.8.2 - Subscriber+ Non-Public List Title Disclosure via wprm_search_lists

Assigner: WPScan
Reserved: 08.09.2026 Published: 23.09.2026 Updated: 23.09.2026

The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.

Product Status

Vendor Unknown
Product WP Recipe Maker
Versions Default: unaffected
  • affected from 0 to 10.8.2 (excl.)

Credits

  • Abdullah Kareem finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE