PT-2026-47275 · WordPress · Recipe Card Blocks Lite

Athiwat Tiprasaharn

+1

·

Published

2026-06-08

·

Updated

2026-06-08

·

CVE-2026-3011

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Recipe Card Blocks Lite versions prior to 3.4.14
Description The Recipe Card Blocks Lite plugin for WordPress contains a Stored Cross-Site Scripting issue. The WPZOOM Helpers::deserialize block attributes() function converts unicode-encoded sequences back into HTML characters after sanitization is performed. This allows authenticated attackers with Author-level access or higher to inject arbitrary web scripts through the summary and notes attributes of the recipe block. These scripts execute when a user views the published post or the print view of the affected recipe.
Recommendations Update the plugin to a version later than 3.4.13.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-3011

Affected Products

Recipe Card Blocks Lite