Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Abhinav Jaswal

#21997of 53,633
10.7Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-21892
4.3
2026-02-25
WordPress · Wp Recipe Maker · CVE-2025-14742
**Name of the Vulnerable Software and Affected Versions** WP Recipe Maker versions prior to 10.2.3 **Description** The WP Recipe Maker plugin for WordPress has a flaw that allows unauthorized access to recipe data. This is due to a missing capability check in the `ajax search recipes` and `ajax get recipe` functions. Attackers with Subscriber-level access or higher can retrieve sensitive recipe information, including drafts, pending recipes, and private recipes that they are not authorized to view. **Recommendations** Update WP Recipe Maker to version 10.2.3 or later.
PT-2025-51812
6.4
2025-12-17
WordPress · Wordpress · CVE-2025-14385
**Name of the Vulnerable Software and Affected Versions** WP Recipe Maker plugin for WordPress versions up to and including 10.2.3 **Description** The WP Recipe Maker plugin for WordPress is susceptible to Stored Cross-Site Scripting. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the wprm-recipe-roundup-item shortcode. Specifically, the 'name' parameter is vulnerable. Authenticated attackers with Contributor-level access or higher can inject arbitrary web scripts into pages. These scripts will execute when a user accesses the injected page. **Recommendations** Update the WP Recipe Maker plugin to a version later than 10.2.3.