Cooked <= 1.11.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Cooked plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.11.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that w...
- CVSS:
- 4.4
- Affected:
- up to 1.11.3
- Fixed in:
- 1.11.4
- Disclosed:
- Dec 31, 2025
CVE-2025-62989 on NVD →
Cooked – Recipe Management [cooked] <= 1.11.2 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Boxy Studio Cooked allows Stored XSS.This issue affects Cooked: from n/a through 1.11.2.
- Affected:
- up to 1.11.2
- Fix:
- No patched version reported
- Disclosed:
- Dec 31, 2025
CVE-2025-62989 on NVD →
Cooked <= 1.11.3 - Missing Authorization
medium
The Cooked plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.11.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.11.3
- Fixed in:
- 1.11.4
- Disclosed:
- Dec 24, 2025
CVE-2025-68586 on NVD →
Cooked – Recipe Management [cooked] <= 1.11.2 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in Gora Tech Cooked cooked allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cooked: from n/a through <= 1.11.2.
- Affected:
- up to 1.11.2
- Fix:
- No patched version reported
- Disclosed:
- Dec 24, 2025
CVE-2025-68586 on NVD →
Cooked – Recipe Management [cooked] < 1.8.1 (closed)
unknown
[en] Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the ‘[cooked-timer]’ shortcode in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers wi...
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Aug 5, 2024
CVE-2024-41816 on NVD →
Cooked – Recipe Management <= 1.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Cooked – Recipe Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cooked-timer' shortcode in all versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker...
- CVSS:
- 6.4
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.1
- Disclosed:
- Aug 4, 2024
CVE-2024-41816 on NVD →
Cooked – Recipe Management [cooked] < 1.8.0 (closed)
unknown
<p>WordPress Cooked Plugin <= 1.7.15.4 is vulnerable to Cross Site Request Forgery (CSRF)</p><p>Software: Cooked</p><p>Link: https://wordpress.org/plugins/cooked/#developers</p><p>Affected Version <= 1.7.15.4</p><p>Fixed in version 1.8.0 </p>
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Jul 18, 2024
Cooked – Recipe Management [cooked] < 1.8.0 (closed)
unknown
<p>WordPress Cooked Plugin <= 1.7.15.4 is vulnerable to Content Injection</p><p>Software: Cooked</p><p>Link: https://wordpress.org/plugins/cooked/#developers</p><p>Affected Version <= 1.7.15.4</p><p>Fixed in version 1.8.0 </p>
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Jul 18, 2024
Cooked – Recipe Management <= 1.7.15.4 - Cross-Site Request Forgery to Template Apply
medium
The Cooked – Recipe Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.15.4. This is due to missing or incorrect nonce validation on the cooked_save_default_bulk action. This makes it possible for unauthenticated attackers to apply templates in bulk via...
- CVSS:
- 5.4
- Affected:
- up to 1.7.15.4
- Fixed in:
- 1.8.0
- Disclosed:
- Jul 17, 2024
CVE-2024-39681 on NVD →
Cooked – Recipe Management <= 1.7.15.4 - Authenticated (Contributor+) HTML Injection
medium
The Cooked – Recipe Management plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.7.15.4. This is due to the plugin not properly escaping/validating input to _recipe_settings. This makes it possible for authenticated attackers, with contributor-level access and above, to inject...
- CVSS:
- 5
- Affected:
- up to 1.7.15.4
- Fixed in:
- 1.8.0
- Disclosed:
- Jul 17, 2024
CVE-2024-39682 on NVD →
Cooked – Recipe Management <= 1.7.15.4 - Cross-Site Request Forgery to Template Reset
medium
The Cooked – Recipe Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.15.4. This is due to missing or incorrect nonce validation on the cooked_load_default AJAX action. This makes it possible for unauthenticated attackers to reset templates via a forge...
- CVSS:
- 4.3
- Affected:
- up to 1.7.15.4
- Fixed in:
- 1.8.0
- Disclosed:
- Jul 17, 2024
CVE-2024-39679 on NVD →
Cooked – Recipe Management <= 1.7.15.4 - Cross-Site Request Forgery via cooked_get_recipe_ids
medium
The Cooked – Recipe Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.15.4. This is due to missing or incorrect nonce validation on the cooked_get_recipe_ids AJAX action. This makes it possible for unauthenticated attackers to trigger a recipe get requ...
- CVSS:
- 4.3
- Affected:
- up to 1.7.15.4
- Fixed in:
- 1.8.0
- Disclosed:
- Jul 17, 2024
CVE-2024-39678 on NVD →
Cooked – Recipe Management <= 1.7.15.4 - Cross-Site Request Forgery to Settings Update
medium
The Cooked – Recipe Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.15.4. This is due to missing or incorrect nonce validation on the cooked_save_default AJAX action. This makes it possible for unauthenticated attackers to update the default_content...
- CVSS:
- 4.3
- Affected:
- up to 1.7.15.4
- Fixed in:
- 1.8.0
- Disclosed:
- Jul 17, 2024
CVE-2024-39680 on NVD →
Cooked – Recipe Management [cooked] < 1.8.0 (closed)
unknown
[en] Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing a...
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Jul 17, 2024
CVE-2024-39680 on NVD →
Cooked – Recipe Management [cooked] < 1.8.0 (closed)
unknown
[en] Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing a...
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Jul 17, 2024
CVE-2024-39679 on NVD →
Cooked – Recipe Management [cooked] < 1.8.0 (closed)
unknown
[en] Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing an action they...
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Jul 17, 2024
CVE-2024-39678 on NVD →
Cooked – Recipe Management [cooked] < 1.8.0 (closed)
unknown
[en] Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitra...
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Jul 17, 2024
CVE-2024-39682 on NVD →
Cooked – Recipe Management [cooked] < 1.8.0 (closed)
unknown
[en] Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing a...
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.0
- Disclosed:
- Jul 17, 2024
CVE-2024-39681 on NVD →
Cooked – Recipe Management <= Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Cooked – Recipe Management recipe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_recipe_settings[post_title]` parameter in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contribut...
- CVSS:
- 6.4
- Affected:
- up to 1.7.15.4
- Fixed in:
- 1.8.0
- Disclosed:
- Jun 13, 2024
CVE-2024-37308 on NVD →
Cooked – Recipe Management [cooked] < 1.7.15.1 (closed)
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Boxy Studio Cooked plugin <= 1.7.13 versions.
- Affected:
- up to 1.7.15.1
- Fixed in:
- 1.7.15.1
- Disclosed:
- Oct 2, 2023
CVE-2023-44477 on NVD →
Cooked <= 1.7.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Cooked plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrar...
- CVSS:
- 6.4
- Affected:
- up to 1.7.14
- Fixed in:
- 1.7.15.1
- Disclosed:
- Sep 29, 2023
CVE-2023-44477 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 1.1.12
- Fixed in:
- 1.1.13
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Cooked <= 1.7.9 - Reflected Cross-Site Scripting
medium
The Cooked plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...
- CVSS:
- 6.1
- Affected:
- up to 1.7.9
- Fixed in:
- 1.7.9.1
- Disclosed:
- Jun 21, 2021
Cooked – Recipe Management [cooked] < 1.7.9.1 (closed)
unknown
The Cooked plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...
- Affected:
- up to 1.7.9.1
- Fixed in:
- 1.7.9.1
- Disclosed:
- Jun 21, 2021
Cooked – Recipe Management [cooked] < 1.7.5.6 (closed)
unknown
[en] The Cooked Pro WordPress plugin before 1.7.5.6 was affected by unauthenticated reflected Cross-Site Scripting issues, due to improper sanitisation of user input while being output back in pages as an arbitrary attribute.
- Affected:
- up to 1.7.5.6
- Fixed in:
- 1.7.5.6
- Disclosed:
- Apr 22, 2021
CVE-2021-24233 on NVD →
Cooked – Recipe Management [cooked] < 1.1.13 (closed)
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.1.13
- Fixed in:
- 1.1.13
CVE-2023-33999 on NVD →
Cooked – Recipe Management [cooked] < 1.7.9.1 (closed)
unknown
The plugin was vulnerable to Unauthenticated Reflected Cross-Site Scripting (XSS).
For clarification, this vulnerability is separate to the similar vulnerability CVE-2021-24233.
- Affected:
- up to 1.7.9.1
- Fixed in:
- 1.7.9.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database