DIRAS TAKE
Urgent: public exploit code exists for this flaw, so sites running WP Recipe Maker 10.8.1 or earlier with public comments should act now to block or moderate comments and follow vendor guidance.
What is CVE-2026-89274?
Unauthenticated attackers can cause WP Recipe Maker to execute registered WordPress shortcodes server-side and expose sensitive data embedded in recipe metadata. CVE-2026-89274 affects WP Recipe Maker versions 10.8.1 and earlier and requires the attacker to submit a rated comment whose wprm-comment-rating entry is approved (either via auto-approval or moderator action) so the injected shortcode is processed on recipe page render.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Which versions of brechtvds WP Recipe Maker are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 10.x | 10.8.1 and earlier |
Is CVE-2026-89274 being exploited?
Public exploit code is available.
How to fix CVE-2026-89274
- If possible, disable or remove the WP Recipe Maker plugin until a vendor patch is available.
- Require manual moderation of comments and block or review wprm-comment-rating submissions before approval.
- Strip or disallow shortcode tokens in user-supplied comment content via filters or input sanitization.
- Monitor web logs and recipe page responses for unexpected shortcode output and sensitive data disclosure.
Frequently asked questions
Is CVE-2026-89274 being actively exploited?
Public exploit code is available for CVE-2026-89274, increasing the risk of active exploitation.
Which WP Recipe Maker versions are affected by CVE-2026-89274?
WP Recipe Maker versions 10.8.1 and earlier are affected by CVE-2026-89274.
Is there a patch for CVE-2026-89274?
There is no fixed version listed for CVE-2026-89274; follow vendor guidance and apply mitigations until a patch is released.
Does CVE-2026-89274 require authentication?
The vulnerability can be triggered by unauthenticated attackers, but successful exploitation requires the attacker's rated comment to be approved on the site.
References
- nvd.nist.gov/vuln/detail/CVE-2026-89274
- cve.org/CVERecord?id=CVE-2026-89274
- wordfence.com/threat-intel/vulnerabilities/id/d6ad49ff-85eb-4d05-ba23-51d89695add3?source=cve
- plugins.trac.wordpress.org/browser/wp-recipe-maker/tags/10.8.1/includes/public/class-wprm-metadata.php#L553
- plugins.trac.wordpress.org/browser/wp-recipe-maker/tags/10.8.1/includes/public/class-wprm-metadata.php#L1028
- plugins.trac.wordpress.org/browser/wp-recipe-maker/tags/10.8.1/includes/public/class-wprm-metadata.php#L181
- plugins.trac.wordpress.org/changeset?reponame=&old=3699793%40wp-recipe-maker&new=3699793%40wp-recipe-maker
- All brechtvds CVEs on CVE Radar
- CVEs published in September 2026