Impact
The vulnerability is a SQL injection flaw present in the WordPress Recipe Maker For Your Food Blog from Zip Recipes plugin versions 8.2.7 and earlier. Because the plugin fails to properly sanitize user input in the contributor functionality, an attacker can inject arbitrary SQL statements. This could allow the attacker to read, modify, or delete data stored in the site’s database, and potentially compromise the whole application if executable SQL is injected.
Affected Systems
The affected system is the WordPress plugin "Recipe Maker For Your Food Blog from Zip Recipes" developed by Igor Benic. All installations of the plugin running version 8.2.7 or older are vulnerable. The plugin is commonly used on WordPress food‑blog sites, so a large number of public and private sites may be impacted if they are still running the susceptible version.
Risk and Exploitability
The CVSS score of 8.5 indicates a high level of severity. The EPSS score is not available, but the issue is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. The likely attack vector is via the contributor submission interface, which may be exposed to authenticated or unauthenticated users depending on site configuration. An attacker who can submit content through that interface can insert malicious SQL and retrieve or alter database records.
OpenCVE Enrichment