Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the ‘[cooked-timer]’ shortcode in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with subscriber-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a compromised page. This issue has been addressed in release version 1.8.1. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-39201 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the ‘[cooked-timer]’ shortcode in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with subscriber-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a compromised page. This issue has been addressed in release version 1.8.1. All users are advised to upgrade. There are no known workarounds for this vulnerability. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 07 Feb 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Boxystudio
Boxystudio cooked |
|
| CPEs | cpe:2.3:a:boxystudio:cooked:*:*:*:*:pro:wordpress:*:* | |
| Vendors & Products |
Boxystudio
Boxystudio cooked |
Thu, 08 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goratech
Goratech cooked |
|
| CPEs | cpe:2.3:a:goratech:cooked:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Goratech
Goratech cooked |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-08T13:28:33.622Z
Reserved: 2024-07-22T13:57:37.137Z
Link: CVE-2024-41816
Updated: 2024-08-08T13:28:27.909Z
Status : Analyzed
Published: 2024-08-05T20:15:35.630
Modified: 2025-02-07T16:36:14.617
Link: CVE-2024-41816
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD