Impact
The WP Recipe Maker plugin is vulnerable to a stored cross‑site scripting flaw via the 'name' attribute in the wprm‑recipe‑roundup‑item shortcode. This weakness arises from insufficient input sanitization and output escaping for user‑supplied attributes. An attacker with Contributor access can embed arbitrary JavaScript that will execute in the browsers of any user who views a page containing the contaminated shortcode. The resulting attack can lead to session hijacking, credential theft, defacement or the execution of malicious code within the site context. The flaw is classified as CWE‑79.
Affected Systems
WordPress sites running the WP Recipe Maker plugin version 10.2.3 or earlier are affected. The vulnerability exists in all releases up to and including 10.2.3 of the plugin.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score of less than 1% signals a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA KEV. Exploitation requires an authenticated attacker who holds Contributor or higher privileges on the WordPress installation, and the attacker must be able to insert content via the recipe roundup shortcode.
OpenCVE Enrichment