CVE-2026-86602: Unknown Wp Recipe Maker

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes.

Affected products

  • Unknown Wp Recipe Maker: from 10.3.0, before 10.8.2 (fixed in 10.8.2)

Published 2026-09-23. Last modified 2026-09-23.