Impact
The plugin sanitizes recipe metadata by recursively calling the WordPress shortcode engine on each scalar field, including the reviewBody field that is filled from comment content. Because the engine executes before the sanitizer runs, an attacker can embed a shortcode in an approved comment and have it executed on every page that renders the recipe. The shortcode’s output is then inserted into the page’s JSON‑LD metadata, exposing private or sensitive information to all visitors. The flaw therefore enables the execution of any registered shortcode, which can be used to read or manipulate data on the site.
Affected Systems
WP Recipe Maker by brechtvds, all releases up to and including version 10.8.1, on WordPress sites that use the wprm-comment-rating feature.
Risk and Exploitability
The CVSS score is 9.1, indicating critical severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers do not need credentials; they simply submit a comment containing a shortcode that passes the site’s approval threshold, whether by auto‑approval or moderator action. Once approved, the injected shortcode runs on every recipe page render, exposing its output to the public.
OpenCVE Enrichment