Impact
The WP Recipe Maker Premium plugin contains a stored cross‑site scripting flaw that allows any authenticated user with contributor or higher privileges to embed arbitrary JavaScript via the 'wprm‑call‑to‑action' shortcode. Because the plugin does not sanitize or escape user supplied shortcode attributes, a malicious script can be stored and later executed for anyone who visits a page containing the shortcode. Executed scripts can steal session cookies, deface content, or perform further phishing or credential‑stealing attacks.
Affected Systems
Bootstrapped Ventures WP Recipe Maker Premium is affected in all releases up to and including version 10.5.0. Any WordPress installation running any of these versions and with contributors or higher users is vulnerable. Upgrading to 10.5.1 or later removes the flaw.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires an authenticated user with at least contributor access to deliver the malicious payload, so the attack vector is credential‑based and limited to sites where an attacker can gain such privileges. An attacker could potentially use the stored script to hijack other users’ sessions or deface the site once they have logged in. While no public exploits are documented, the moderate score and credential requirement suggest a moderate threat, especially on sites with many contributor accounts.
OpenCVE Enrichment