Vulnerabilities and security researches forcooked cooked
Direction: ascendingJun 10, 2024
Cooked – Recipe Management # CVE-2023-44477
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 02, 2023
- Research Description
- Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Boxy Studio Cooked plugin <= 1.7.13 versions.
- Affected versions
-
max 1.7.15.1.
- Status
-
vulnerable
Cooked – Recipe Management # CVE-2021-24233
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 23, 2021
- Research Description
- The Cooked Pro WordPress plugin before 1.7.5.6 was affected by unauthenticated reflected Cross-Site Scripting issues, due to improper sanitisation of user input while being output back in pages as an arbitrary attribute.
- Affected versions
-
max 1.1.13.
- Status
-
vulnerable
Jul 20, 2024
Cooked – Recipe Management # CVE-2024-39678
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 18, 2024
- Research Description
- Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing an action they didn't intend to perform under their current authentication. This issue has been addressed in release version 1.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
- Affected versions
-
max 1.8.0.
- Status
-
vulnerable
Cooked – Recipe Management # CVE-2024-39680
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 18, 2024
- Research Description
- Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing an action they didn't intend to perform under their current authentication. This issue has been addressed in release version 1.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
- Affected versions
-
max 1.8.0.
- Status
-
vulnerable
Cooked – Recipe Management # CVE-2024-39679
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 18, 2024
- Research Description
- Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing an action they didn't intend to perform under their current authentication. This issue has been addressed in release version 1.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
- Affected versions
-
max 1.8.0.
- Status
-
vulnerable
Cooked – Recipe Management # CVE-2024-39682
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 18, 2024
- Research Description
- Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary HTML in pages that will be shown whenever a user accesses a compromised page. This issue has been addressed in release version 1.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
- Affected versions
-
max 1.8.0.
- Status
-
vulnerable
Cooked – Recipe Management # CVE-2024-39681
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 18, 2024
- Research Description
- Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing an action they didn't intend to perform under their current authentication. This issue has been addressed in release version 1.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
- Affected versions
-
max 1.8.0.
- Status
-
vulnerable
Aug 07, 2024
Cooked – Recipe Management # CVE-2024-41816
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 06, 2024
- Research Description
- Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the ‘[cooked-timer]’ shortcode in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with subscriber-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a compromised page. This issue has been addressed in release version 1.8.1. All users are advised to upgrade. There are no known workarounds for this vulnerability.
- Affected versions
-
max 1.8.1.
- Status
-
vulnerable
Jan 11, 2026
Cooked – Recipe Management # CVE-2025-62989
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 31, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Boxy Studio Cooked allows Stored XSS.This issue affects Cooked: from n/a through 1.11.2.
- Affected versions
-
max 1.11.2.
- Status
-
vulnerable
Cooked – Recipe Management # CVE-2025-68586
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 24, 2025
- Research Description
- Missing Authorization vulnerability in Gora Tech Cooked cooked allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cooked: from n/a through <= 1.11.2.
- Affected versions
-
max 1.11.2.
- Status
-
vulnerable
Jun 12, 2026
Cooked – Recipe Management # CVE-2023-33999
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 11, 2026
- Research Description
- Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This issue affects WP Mail Log: from n/a through 1.0.2.
- Affected versions
-
max 1.1.13.
- Status
-
vulnerable