Impact
The Recipe Card Blocks Lite plugin uses a deserialization routine that rewrites unicode sequences into HTML characters after sanitization. This flaw allows an authenticated user with Author or higher privileges to inject arbitrary JavaScript into the recipe block’s 'summary' and 'notes' fields. Once injected, scripts execute in the browser of any user who views the post or the print view, potentially enabling session hijacking, defacement, or data theft.
Affected Systems
WordPress sites running the Recipe Card Blocks Lite plugin version 3.4.13 or earlier, provided by wpzoom. The vulnerability targets the recipe block implementation and is present throughout all affected releases.
Risk and Exploitability
The CVSS score is 6.4, indicating a moderate severity. Exploitation remains possible once an author or better attacker edits a recipe, and the risk is amplified on sites with many authors. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the attack path does not require special configuration beyond legitimate editorial access.
OpenCVE Enrichment