Description
The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the `reviewBody` field, which is populated verbatim from the `comment_content` of approved `wprm-comment-rating` comments — without sanitizing or stripping shortcode tokens before execution; the subsequent `wp_strip_all_tags()` and `strip_shortcodes()` calls operate only on the output string after execution has already fully occurred, providing no protection against server-side shortcode invocation. This makes it possible for unauthenticated attackers to execute arbitrary registered WordPress shortcodes server-side on every recipe page render, causing shortcode output — such as attachment captions, private post fields, or other data exposed by installed shortcodes — to be embedded in the page's JSON-LD `reviewBody` metadata and disclosed to all visitors who load the recipe page. Successful exploitation requires the attacker's rated comment to pass the site's comment approval threshold, either via auto-approval or moderator action, before the injected shortcode begins executing on page loads.
Published: 2026-09-19
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary WordPress shortcode execution leading to data disclosure
Action: Immediate patch
AI Analysis

Impact

The plugin sanitizes recipe metadata by recursively calling the WordPress shortcode engine on each scalar field, including the reviewBody field that is filled from comment content. Because the engine executes before the sanitizer runs, an attacker can embed a shortcode in an approved comment and have it executed on every page that renders the recipe. The shortcode’s output is then inserted into the page’s JSON‑LD metadata, exposing private or sensitive information to all visitors. The flaw therefore enables the execution of any registered shortcode, which can be used to read or manipulate data on the site.

Affected Systems

WP Recipe Maker by brechtvds, all releases up to and including version 10.8.1, on WordPress sites that use the wprm-comment-rating feature.

Risk and Exploitability

The CVSS score is 9.1, indicating critical severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers do not need credentials; they simply submit a comment containing a shortcode that passes the site’s approval threshold, whether by auto‑approval or moderator action. Once approved, the injected shortcode runs on every recipe page render, exposing its output to the public.

Generated by OpenCVE AI on September 19, 2026 at 10:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update WP Recipe Maker to a version newer than 10.8.1 that removes the recursive shortcode call from metadata sanitization.
  • Disable automatic comment approval or enforce manual moderation so that attacker‑supplied shortcodes cannot be approved.
  • Remove or sanitize any existing wprm-comment-rating comments that contain shortcode tokens and delete all other ratings that could be exploited.
  • As a temporary measure, restrict or disable shortcodes that can expose sensitive data, or remove them entirely if they are not required.

Generated by OpenCVE AI on September 19, 2026 at 10:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Brechtvds
Brechtvds wp Recipe Maker
Wordpress
Wordpress wordpress
Vendors & Products Brechtvds
Brechtvds wp Recipe Maker
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the `reviewBody` field, which is populated verbatim from the `comment_content` of approved `wprm-comment-rating` comments — without sanitizing or stripping shortcode tokens before execution; the subsequent `wp_strip_all_tags()` and `strip_shortcodes()` calls operate only on the output string after execution has already fully occurred, providing no protection against server-side shortcode invocation. This makes it possible for unauthenticated attackers to execute arbitrary registered WordPress shortcodes server-side on every recipe page render, causing shortcode output — such as attachment captions, private post fields, or other data exposed by installed shortcodes — to be embedded in the page's JSON-LD `reviewBody` metadata and disclosed to all visitors who load the recipe page. Successful exploitation requires the attacker's rated comment to pass the site's comment approval threshold, either via auto-approval or moderator action, before the injected shortcode begins executing on page loads.
Title WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Brechtvds Wp Recipe Maker
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:26.322Z

Reserved: 2026-09-11T11:03:45.111Z

Link: CVE-2026-89274

cve-icon Vulnrichment

Updated: 2026-09-19T13:57:04.009Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T03:17:16.587

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-89274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:30:13Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')