CVE-2026-86603: CWE-200 Information Exposure in WP Recipe Maker
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.
AI Analysis
Technical Summary
The WP Recipe Maker plugin for WordPress prior to version 10.8.2 contains an authorization bypass in an AJAX action. This vulnerability (CWE-200) permits any authenticated user to retrieve sensitive information—specifically, the IDs and titles of unpublished lists belonging to other users—without proper permission verification.
Potential Impact
An attacker with any authenticated user account can access information about other users' unpublished recipe lists, potentially exposing sensitive or private content. This exposure is limited to metadata (IDs and titles) and does not indicate direct access to the full unpublished content or other user data.
Mitigation Recommendations
Upgrade WP Recipe Maker to version 10.8.2 or later, where this authorization issue has been fixed. Since the vulnerability is resolved in this version, no additional mitigation steps are required beyond applying the official update.
CVE-2026-86603: CWE-200 Information Exposure in WP Recipe Maker
Description
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.
CVSS v3.1
Score 4.3medium
Affected software
WP Recipe Maker
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The WP Recipe Maker plugin for WordPress prior to version 10.8.2 contains an authorization bypass in an AJAX action. This vulnerability (CWE-200) permits any authenticated user to retrieve sensitive information—specifically, the IDs and titles of unpublished lists belonging to other users—without proper permission verification.
Potential Impact
An attacker with any authenticated user account can access information about other users' unpublished recipe lists, potentially exposing sensitive or private content. This exposure is limited to metadata (IDs and titles) and does not indicate direct access to the full unpublished content or other user data.
Mitigation Recommendations
Upgrade WP Recipe Maker to version 10.8.2 or later, where this authorization issue has been fixed. Since the vulnerability is resolved in this version, no additional mitigation steps are required beyond applying the official update.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-08T08:38:33.171Z
- State
- PUBLISHED
Threat ID: 6ab36d42f7a7c541065abcb1
Added to database: 09/23/2026, 06:10:10 UTC
Last enriched: 09/23/2026, 06:19:03 UTC
Last updated: 09/23/2026, 11:03:50 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.