Vulnerabilities and security researches fordelicious-recipes delicious-recipes
Direction: ascendingWP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes) # 69b9546984aa5697575c7b6215bb7578e9e1b2c0
- CVE, Research URL
- Home page URL
-
Security reports for WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)
- Date
- Feb 28, 2022
- Research Description
- WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) [delicious-recipes] < 1.3.5 WordPress Delicious Recipes – WordPress Recipe plugin <= 1.3.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Delicious Recipes – WordPress Recipe plugin (versions <= 1.3.4).
- Affected versions
-
max 1.3.5.
- Status
-
vulnerable
WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2024-43935
- CVE, Research URL
- Home page URL
-
Security reports for WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)
- Date
- Aug 29, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Delicious Delicious Recipes – WordPress Recipe Plugin allows Stored XSS.This issue affects Delicious Recipes – WordPress Recipe Plugin: from n/a through 1.6.7.
- Affected versions
-
max 1.6.8.
- Status
-
vulnerable
WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2024-7626
- CVE, Research URL
- Home page URL
-
Security reports for WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)
- Date
- Sep 11, 2024
- Research Description
- The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file movement and reading due to insufficient file path validation in the save_edit_profile_details() function in all versions up to, and including, 1.6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php). This can also lead to the reading of arbitrary files that may contain sensitive information like wp-config.php.
- Affected versions
-
max 1.7.0.
- Status
-
vulnerable
WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2022-4974
- CVE, Research URL
- Home page URL
-
Security reports for WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)
- Date
- Oct 16, 2024
- Research Description
- The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
- Affected versions
-
max 1.3.5.
- Status
-
vulnerable
WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2025-54023
- CVE, Research URL
- Home page URL
-
Security reports for WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)
- Date
- Jul 16, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious delicious-recipes allows DOM-Based XSS.This issue affects WP Delicious: from n/a through <= 1.8.4.
- Affected versions
-
max 1.8.5.
- Status
-
vulnerable
WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2025-58605
- CVE, Research URL
- Home page URL
-
Security reports for WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)
- Date
- Sep 03, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious delicious-recipes allows Stored XSS.This issue affects WP Delicious: from n/a through <= 1.8.7.
- Affected versions
-
max 1.8.8.
- Status
-
vulnerable
WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2025-11755
- CVE, Research URL
- Home page URL
-
Security reports for WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)
- Date
- Nov 01, 2025
- Research Description
- The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file uploads when importing recipes via CSV in all versions up to, and including, 1.9.0. This flaw allows an attacker with at least Contributor-level permissions to upload a malicious PHP file by providing a remote URL during a recipe import process, leading to Remote Code Execution (RCE).
- Affected versions
-
max 1.9.1.
- Status
-
vulnerable
WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2025-67548
- CVE, Research URL
- Home page URL
-
Security reports for WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)
- Date
- Dec 09, 2025
- Research Description
- Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delicious: from n/a through <= 1.9.1.
- Affected versions
-
max 1.9.2.
- Status
-
vulnerable
WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2026-39528
- CVE, Research URL
- Home page URL
-
Security reports for WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)
- Date
- Apr 08, 2026
- Research Description
- Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delicious: from n/a through <= 1.9.5.
- Affected versions
-
max 1.9.6.
- Status
-
vulnerable
WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes) # e545458bfa395fae0d7ab5d793b7ad07439195bc
- CVE, Research URL
- Home page URL
-
Security reports for WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)
- Date
- Feb 28, 2022
- Research Description
- WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) [delicious-recipes] < 1.3.5 WordPress Delicious Recipes – WordPress Recipe plugin <= 1.3.4 - Sensitive Information Disclosure vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress Delicious Recipes – WordPress Recipe plugin (versions <= 1.3.4).
- Affected versions
-
max 1.3.5.
- Status
-
vulnerable
WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes) # 6d8910c719b2a132ec93828cd37e418b19cac960
- CVE, Research URL
- Home page URL
-
Security reports for WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)
- Date
- Mar 04, 2022
- Research Description
- WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) [delicious-recipes] < 1.3.5 Freemius SDK <= 2.4.2 - Missing Authorization Checks The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
- Affected versions
-
max 1.3.5.
- Status
-
vulnerable
WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2026-15099
- CVE, Research URL
- Home page URL
-
Security reports for WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)
- Date
- Jul 16, 2026
- Research Description
- The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and including, 1.10.2. This is due to insufficient input sanitization and output escaping in the wrap_direction_text() function, which interpolates the user-supplied href value from nested link nodes ($node['props']['href']) directly into an anchor tag via sprintf() at line 1627 without esc_url() or any URL scheme validation. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts (including javascript: URIs) in pages that will execute whenever a user (such as an editor or administrator previewing the pending post) accesses an injected page and clicks the malicious link.
- Affected versions
-
max 1.10.3.
- Status
-
vulnerable
WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2026-14305
- CVE, Research URL
- Home page URL
-
Security reports for WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)
- Date
- Jul 30, 2026
- Research Description
- The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to modify limited post metadata (a like counter and an associated identifier list) on arbitrary posts, including inflating the counter and growing the stored metadata without bound.
- Affected versions
-
max 1.10.2.
- Status
-
vulnerable
WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes) # CVE-2026-92411
- CVE, Research URL
- Home page URL
-
Security reports for WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)
- Date
- Sep 26, 2026
- Research Description
- The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it on the front end, allowing users with the Contributor role and above to inject arbitrary HTML tags, including script tags, which execute when the recipe page is viewed.
- Affected versions
-
max 1.10.8.
- Status
-
vulnerable