WP Recipe Maker

26 known CVEs 50K+ active installs

Scan My Site Free

UNKNOWN: 26
Known Vulnerabilities 26
CVE-2026-1558 UNKNOWN EPSS 0.2%
Published 2026-02-27 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, and including, 10.3.2. This is due to the /wp-json/wp-recipe-maker/v1/integratio
CVE-2025-14742 UNKNOWN EPSS 0.1%
Published 2026-02-25 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ajax_search_recipes' and 'ajax_get_recipe' functions in all versions up
CVE-2025-15527 UNKNOWN EPSS 0.2%
Published 2026-01-16 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2 via the api_get_post_summary function due to insufficient restrictions on which
CVE-2025-14385 UNKNOWN EPSS 0.2%
Published 2025-12-17 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 10.2.3 due to insufficient input sanitization and o
CVE-2024-0383 UNKNOWN EPSS 0.4%
Published 2024-06-19 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [wprm-recipe-instructions] and [wprm-recipe-ingredients] shortcodes in all versions up to, and in
CVE-2024-0383 UNKNOWN EPSS 0.4%
Published 2024-06-19 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [wprm-recipe-instructions] and [wprm-recipe-ingredients] shortcodes in all versions up to, and in
CVE-2024-3490 UNKNOWN EPSS 0.2%
Published 2024-05-02 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wprm-recipe-roundup-item shortcode in all versions up to, and including, 9.3.1 due to insufficien
CVE-2024-3490 UNKNOWN EPSS 0.2%
Published 2024-05-02 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wprm-recipe-roundup-item shortcode in all versions up to, and including, 9.3.1 due to insufficien
CVE-2024-1571 UNKNOWN EPSS 0.4%
Published 2024-04-09 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video Embed parameter in all versions up to, and including, 9.2.1 due to insufficient input sanitization a
CVE-2024-1571 UNKNOWN EPSS 0.4%
Published 2024-04-09 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video Embed parameter in all versions up to, and including, 9.2.1 due to insufficient input sanitization a
CVE-2024-1206 UNKNOWN EPSS 0.5%
Published 2024-02-29 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to SQL Injection via the 'recipes' parameter in all versions up to, and including, 9.1.2 due to insufficient escaping on the user supplied parame
CVE-2024-1206 UNKNOWN EPSS 0.5%
Published 2024-02-29 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to SQL Injection via the 'recipes' parameter in all versions up to, and including, 9.1.2 due to insufficient escaping on the user supplied parame
CVE-2024-0384 UNKNOWN EPSS 0.4%
Published 2024-02-05 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Notes in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output esc
CVE-2024-0384 UNKNOWN EPSS 0.4%
Published 2024-02-05 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Notes in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output esc
CVE-2024-0382 UNKNOWN EPSS 0.4%
Published 2024-02-05 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 due to unrestricted use of the 'header_t
CVE-2024-0382 UNKNOWN EPSS 0.4%
Published 2024-02-05 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 due to unrestricted use of the 'header_t
CVE-2024-0380 UNKNOWN EPSS 0.5%
Published 2024-02-05 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 9.1.0 via the 'icon' attribute used in Shortcodes. This makes it possible for authen
CVE-2024-0380 UNKNOWN EPSS 0.5%
Published 2024-02-05 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 9.1.0 via the 'icon' attribute used in Shortcodes. This makes it possible for authen
CVE-2024-0255 UNKNOWN EPSS 0.4%
Published 2024-02-05 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-recipe-text-share' shortcode in all versions up to, and including, 9.1.0 due to insufficien
CVE-2024-0255 UNKNOWN EPSS 0.4%
Published 2024-02-05 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-recipe-text-share' shortcode in all versions up to, and including, 9.1.0 due to insufficien
CVE-2024-0381 UNKNOWN EPSS 0.5%
Published 2024-01-18 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute in the wprm-recipe-name, wprm-recipe-date, and wprm-recipe-counter shortcodes i
CVE-2024-0381 UNKNOWN EPSS 0.5%
Published 2024-01-18 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute in the wprm-recipe-name, wprm-recipe-date, and wprm-recipe-counter shortcodes i
CVE-2023-6970 UNKNOWN EPSS 0.5%
Published 2024-01-18 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 due to insufficient input sanitization and
CVE-2023-6970 UNKNOWN EPSS 0.5%
Published 2024-01-18 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 due to insufficient input sanitization and
CVE-2023-6958 UNKNOWN EPSS 0.3%
Published 2024-01-18 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 due to insufficient input sanitization a
CVE-2023-6958 UNKNOWN EPSS 0.3%
Published 2024-01-18 · Affected: *
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 due to insufficient input sanitization a

Is WP Recipe Maker running on your site?

A free scan detects your plugins and flags any that match these CVEs.

Scan My Site Free