Description
Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions.
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated Cross‑Site Scripting flaw that appears in versions of the WordPress Recipe Card Blocks for Gutenberg & Elementor plugin up to 3.4.18. An attacker can supply malicious script payloads, which the plugin passes directly to the browser without sanitisation, enabling the execution of arbitrary code within the context of a user’s session. This can lead to defacement, credential theft, and the delivery of further malware. The weakness corresponds to CWE‑79.

Affected Systems

This issue affects the WPZOOM "Recipe Card Blocks for Gutenberg & Elementor" plugin, specifically all releases version 3.4.18 and earlier.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. Although no EPSS value is currently available, the lack of an authentication requirement and the client‑side nature of the flaw signify a low barrier to exploitation. The vulnerability is not listed in the CISA KEV catalog, but because it can be triggered by unauthenticated users, it carries a significant risk profile. The likely attack vector is a crafted request or a user embedding malicious content into the plugin’s fields, which is then rendered in the browser without filtering.

Generated by OpenCVE AI on August 18, 2026 at 17:02 UTC.

Remediation

Vendor Solution

Update the WordPress Recipe Card Blocks for Gutenberg & Elementor Plugin to the latest available version (at least 3.4.19).


OpenCVE Recommended Actions

  • Update the Plugin to version 3.4.19 or later, which contains the patch for this XSS issue.
  • Disable the plugin on any site that cannot apply the update immediately to prevent exposure.
  • Implement additional content sanitization for any data entered via the plugin to ensure no malicious scripts are embedded in rendered pages.

Generated by OpenCVE AI on August 18, 2026 at 17:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpzoom
Wpzoom recipe Card Blocks For Gutenberg & Elementor
Vendors & Products Wordpress
Wordpress wordpress
Wpzoom
Wpzoom recipe Card Blocks For Gutenberg & Elementor

Tue, 18 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions.
Title WordPress Recipe Card Blocks for Gutenberg & Elementor plugin <= 3.4.18 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Wpzoom Recipe Card Blocks For Gutenberg & Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T15:11:31.391Z

Reserved: 2026-08-12T10:51:25.492Z

Link: CVE-2026-73361

cve-icon Vulnrichment

Updated: 2026-08-18T14:59:43.543Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:17:04.503

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-73361

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T17:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')