Impact
The WP Recipe Maker plugin for WordPress allows an authenticated user with Contributor or higher privileges to store arbitrary JavaScript code in the 'notes' field without proper sanitization or escaping. This flaw constitutes a stored cross‑site scripting vulnerability (CWE‑79) that will run whenever a page displaying the stored notes is loaded in a victim’s browser.
Affected Systems
All installations of WP Recipe Maker by brechtvds that are running any version up to and including 10.8.1 on a WordPress site. Sites that have not yet upgraded beyond 10.8.1 are therefore affected.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score of < 1 % shows that the probability of exploitation is very low at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a valid authenticated account with at least Contributor access; once authenticated, the attacker can insert and store malicious JavaScript that will be executed in the browser of any visitor who views the affected page. The impact is limited to the client side and does not involve direct server‑side compromise. Based on typical XSS consequences, it is inferred that the injected scripts may read or modify the content that the victim sees or potentially steal data from that session, though such outcomes are not directly documented by the CVE description.
OpenCVE Enrichment