Description
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video Embed parameter in all versions up to, and including, 9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to the recipe dashboard (which is administrator-only by default but can be assigned to arbitrary capabilities), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17315 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video Embed parameter in all versions up to, and including, 9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to the recipe dashboard (which is administrator-only by default but can be assigned to arbitrary capabilities), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | WP Recipe Maker <= 9.2.1 - Authenticated Stored Cross-Site Scripting via Video Embed |
Wed, 25 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bootstrapped
Bootstrapped wp Recipe Maker |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:bootstrapped:wp_recipe_maker:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Bootstrapped
Bootstrapped wp Recipe Maker |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:59:08.264Z
Reserved: 2024-02-15T21:07:47.566Z
Link: CVE-2024-1571
Updated: 2024-08-01T18:40:21.375Z
Status : Modified
Published: 2024-04-09T19:15:18.417
Modified: 2026-04-08T18:20:43.733
Link: CVE-2024-1571
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD