WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes), CVE-2026-14305
- CVE, Research URL
- Home page URL
-
Security reports for WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)
- Published on
- Jul 30, 2026
- Research Description
- The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to modify limited post metadata (a like counter and an associated identifier list) on arbitrary posts, including inflating the counter and growing the stored metadata without bound.
- Affected versions
-
max 1.10.2.
- Status
-
vulnerable