The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video Embed parameter in all versions up to, and including, 9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to the recipe dashboard (which is administrator-only by default but can be assigned to arbitrary capabilities), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Bootstrapped
Bootstrapped wp Recipe Maker |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:bootstrapped:wp_recipe_maker:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Bootstrapped
Bootstrapped wp Recipe Maker |

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T18:40:21.375Z
Reserved: 2024-02-15T21:07:47.566Z
Link: CVE-2024-1571

Updated: 2024-08-01T18:40:21.375Z

Status : Analyzed
Published: 2024-04-09T19:15:18.417
Modified: 2025-02-27T14:53:37.577
Link: CVE-2024-1571

No data.