CVE-CVE-2026-89274
Severity
CRITICAL
CVSS Score
9.1
Description
The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the `reviewBody` field, which is populated verbatim from the `comment_content` of approved `wprm-comment-rating` comments — without sanitizing or stripping shortcode tokens before execu...
PoCs for CVE-CVE-2026-89274
CVE-2026-89274
General
Python
0
murrez
2026-09-19
CVE-2026-89274-wp-recipe-maker-poc
Buffer Overflow
Python
0
Hassham1
2026-09-23