CVE-2026-86601: Unknown Wp Recipe Maker
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing unauthenticated users to have arbitrary shortcodes executed server side and to read the content of unpublished recipes.
Affected products
- Unknown Wp Recipe Maker: before 10.8.2 (fixed in 10.8.2)
Published 2026-09-23. Last modified 2026-09-23.