{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awp_recipe_makerwp_recipe_makerwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wp_recipe_maker:wp_recipe_maker:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-89274"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Recipe Maker (\u003c= 10.8.1)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","wordpress","cve-2026-89274"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe WP Recipe Maker plugin for WordPress contains a critical vulnerability (CVE-2026-89274) in its metadata sanitization logic. The function \u003ccode\u003eWPRM_Metadata::sanitize_metadata()\u003c/code\u003e recursively processes recipe structured metadata arrays by invoking \u003ccode\u003edo_shortcode()\u003c/code\u003e on scalar fields. Specifically, the \u003ccode\u003ereviewBody\u003c/code\u003e field is populated using the raw \u003ccode\u003ecomment_content\u003c/code\u003e of user-submitted \u003ccode\u003ewprm-comment-rating\u003c/code\u003e comments. Because the plugin performs tag and shortcode stripping only after the \u003ccode\u003edo_shortcode()\u003c/code\u003e call has been executed, it fails to sanitize malicious shortcode tokens. This flaw permits unauthenticated attackers to trigger server-side execution of registered WordPress shortcodes when a recipe page is rendered. Successful exploitation allows for the disclosure of sensitive information, such as private post data or attachment details, which are then rendered into the page's JSON-LD metadata for all visitors to see. The exploit requires the malicious comment to be approved, either through site settings or human intervention.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious comment containing a target WordPress shortcode.\u003c/li\u003e\n\u003cli\u003eAttacker submits the comment through the \u003ccode\u003ewprm-comment-rating\u003c/code\u003e input on a recipe page.\u003c/li\u003e\n\u003cli\u003eThe WordPress site administrator or automated process approves the comment.\u003c/li\u003e\n\u003cli\u003eThe WP Recipe Maker plugin processes the recipe metadata for display.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eWPRM_Metadata::sanitize_metadata()\u003c/code\u003e pulls the raw \u003ccode\u003ecomment_content\u003c/code\u003e into the \u003ccode\u003ereviewBody\u003c/code\u003e field.\u003c/li\u003e\n\u003cli\u003eThe plugin calls \u003ccode\u003edo_shortcode()\u003c/code\u003e on the \u003ccode\u003ereviewBody\u003c/code\u003e string, executing the injected shortcode server-side.\u003c/li\u003e\n\u003cli\u003eThe sensitive data rendered by the shortcode is stored in the JSON-LD structure of the recipe page.\u003c/li\u003e\n\u003cli\u003eAny visitor loading the recipe page receives the sensitive information within the page's JSON-LD output.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk of information disclosure across WordPress installations using the WP Recipe Maker plugin. Attackers can leverage this to exfiltrate private post content, system information, or other data exposed via shortcodes. By embedding this information in publicly accessible JSON-LD metadata, the attacker ensures the leaked data is visible to any browser loading the affected recipe page.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the WP Recipe Maker plugin to a version beyond 10.8.1 immediately to resolve CVE-2026-89274.\u003c/li\u003e\n\u003cli\u003eImplement strict moderation policies for comments on recipe pages to prevent unapproved content from being rendered by the plugin.\u003c/li\u003e\n\u003cli\u003eConduct an audit of all active shortcodes on the WordPress instance to identify those that could expose sensitive data if triggered via this vulnerability.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-19T04:08:39Z","date_published":"2026-09-19T04:08:39Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wp-recipe-maker-rce/","summary":"The WP Recipe Maker plugin for WordPress (\u003c= 10.8.1) is vulnerable to arbitrary shortcode execution due to recursive do_shortcode calls on user-supplied metadata fields.","title":"Arbitrary Shortcode Execution in WP Recipe Maker Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-wp-recipe-maker-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wp_recipe_maker:wp_recipe_maker:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}