cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches fordelicious-recipes delicious-recipes

Direction: ascending
Jun 06, 2024

WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes) # 69b9546984aa5697575c7b6215bb7578e9e1b2c0

Date
Feb 28, 2022
Research Description
WP Delicious &#8211; Recipe Plugin for Food Bloggers (formerly Delicious Recipes) [delicious-recipes] < 1.3.5 WordPress Delicious Recipes – WordPress Recipe plugin <= 1.3.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Delicious Recipes – WordPress Recipe plugin (versions <= 1.3.4).
Affected versions
max 1.3.5.
Status
vulnerable
Aug 29, 2024

WP Delicious &#8211; Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2024-43935

CVE, Research URL

CVE-2024-43935

Date
Aug 29, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Delicious Delicious Recipes – WordPress Recipe Plugin allows Stored XSS.This issue affects Delicious Recipes – WordPress Recipe Plugin: from n/a through 1.6.7.
Affected versions
max 1.6.8.
Status
vulnerable
Sep 12, 2024

WP Delicious &#8211; Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2024-7626

CVE, Research URL

CVE-2024-7626

Date
Sep 11, 2024
Research Description
The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file movement and reading due to insufficient file path validation in the save_edit_profile_details() function in all versions up to, and including, 1.6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php). This can also lead to the reading of arbitrary files that may contain sensitive information like wp-config.php.
Affected versions
max 1.7.0.
Status
vulnerable
Nov 15, 2024

WP Delicious &#8211; Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
max 1.3.5.
Status
vulnerable
Jul 18, 2025

WP Delicious &#8211; Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2025-54023

CVE, Research URL

CVE-2025-54023

Date
Jul 16, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious delicious-recipes allows DOM-Based XSS.This issue affects WP Delicious: from n/a through <= 1.8.4.
Affected versions
max 1.8.5.
Status
vulnerable
Sep 05, 2025

WP Delicious &#8211; Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2025-58605

CVE, Research URL

CVE-2025-58605

Date
Sep 03, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious delicious-recipes allows Stored XSS.This issue affects WP Delicious: from n/a through <= 1.8.7.
Affected versions
max 1.8.8.
Status
vulnerable
Nov 11, 2025

WP Delicious &#8211; Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2025-11755

CVE, Research URL

CVE-2025-11755

Date
Nov 01, 2025
Research Description
The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file uploads when importing recipes via CSV in all versions up to, and including, 1.9.0. This flaw allows an attacker with at least Contributor-level permissions to upload a malicious PHP file by providing a remote URL during a recipe import process, leading to Remote Code Execution (RCE).
Affected versions
max 1.9.1.
Status
vulnerable
Dec 11, 2025

WP Delicious &#8211; Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2025-67548

CVE, Research URL

CVE-2025-67548

Date
Dec 09, 2025
Research Description
Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delicious: from n/a through <= 1.9.1.
Affected versions
max 1.9.2.
Status
vulnerable
Apr 14, 2026

WP Delicious &#8211; Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2026-39528

CVE, Research URL

CVE-2026-39528

Date
Apr 08, 2026
Research Description
Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delicious: from n/a through <= 1.9.5.
Affected versions
max 1.9.6.
Status
vulnerable
Jun 16, 2026

WP Delicious &#8211; Best WordPress Recipes Plugin (formerly Delicious Recipes) # e545458bfa395fae0d7ab5d793b7ad07439195bc

Date
Feb 28, 2022
Research Description
WP Delicious &#8211; Recipe Plugin for Food Bloggers (formerly Delicious Recipes) [delicious-recipes] < 1.3.5 WordPress Delicious Recipes – WordPress Recipe plugin <= 1.3.4 - Sensitive Information Disclosure vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress Delicious Recipes – WordPress Recipe plugin (versions <= 1.3.4).
Affected versions
max 1.3.5.
Status
vulnerable

WP Delicious &#8211; Best WordPress Recipes Plugin (formerly Delicious Recipes) # 6d8910c719b2a132ec93828cd37e418b19cac960

Date
Mar 04, 2022
Research Description
WP Delicious &#8211; Recipe Plugin for Food Bloggers (formerly Delicious Recipes) [delicious-recipes] < 1.3.5 Freemius SDK <= 2.4.2 - Missing Authorization Checks The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
max 1.3.5.
Status
vulnerable
Jul 17, 2026

WP Delicious &#8211; Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2026-15099

CVE, Research URL

CVE-2026-15099

Date
Jul 16, 2026
Research Description
The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and including, 1.10.2. This is due to insufficient input sanitization and output escaping in the wrap_direction_text() function, which interpolates the user-supplied href value from nested link nodes ($node['props']['href']) directly into an anchor tag via sprintf() at line 1627 without esc_url() or any URL scheme validation. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts (including javascript: URIs) in pages that will execute whenever a user (such as an editor or administrator previewing the pending post) accesses an injected page and clicks the malicious link.
Affected versions
max 1.10.3.
Status
vulnerable
Aug 01, 2026

WP Delicious &#8211; Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2026-14305

CVE, Research URL

CVE-2026-14305

Date
Jul 30, 2026
Research Description
The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to modify limited post metadata (a like counter and an associated identifier list) on arbitrary posts, including inflating the counter and growing the stored metadata without bound.
Affected versions
max 1.10.2.
Status
vulnerable
Sep 28, 2026

WP Delicious &#8211; Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2026-92411

CVE, Research URL

CVE-2026-92411

Date
Sep 26, 2026
Research Description
The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it on the front end, allowing users with the Contributor role and above to inject arbitrary HTML tags, including script tags, which execute when the recipe page is viewed.
Affected versions
max 1.10.8.
Status
vulnerable