cleantalk
Vulnerabilities and Security Researches

WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes), CVE-2026-14305

CVE, Research URL

CVE-2026-14305

Published on
Jul 30, 2026
Research Description
The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to modify limited post metadata (a like counter and an associated identifier list) on arbitrary posts, including inflating the counter and growing the stored metadata without bound.
Affected versions
max 1.10.2.
Status
vulnerable