plugin

Cooked Vulnerabilities

27 known security issues reported for the Cooked WordPress plugin. Most recent disclosed Dec 31, 2025.

12 medium

Running Cooked on your site? Check whether your installed version is affected.

Scan your site free

Cooked <= 1.11.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Cooked plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.11.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that w...

CVSS:
4.4
Affected:
up to 1.11.3
Fixed in:
1.11.4
Disclosed:
Dec 31, 2025

CVE-2025-62989 on NVD →

Cooked &#8211; Recipe Management [cooked] <= 1.11.2 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Boxy Studio Cooked allows Stored XSS.This issue affects Cooked: from n/a through 1.11.2.

Affected:
up to 1.11.2
Fix:
No patched version reported
Disclosed:
Dec 31, 2025

CVE-2025-62989 on NVD →

Cooked <= 1.11.3 - Missing Authorization

medium

The Cooked plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.11.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.11.3
Fixed in:
1.11.4
Disclosed:
Dec 24, 2025

CVE-2025-68586 on NVD →

Cooked &#8211; Recipe Management [cooked] <= 1.11.2 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in Gora Tech Cooked cooked allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cooked: from n/a through <= 1.11.2.

Affected:
up to 1.11.2
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68586 on NVD →

Cooked &#8211; Recipe Management [cooked] < 1.8.1 (closed)

unknown

[en] Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the ‘[cooked-timer]’ shortcode in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers wi...

Affected:
up to 1.8.1
Fixed in:
1.8.1
Disclosed:
Aug 5, 2024

CVE-2024-41816 on NVD →

Cooked – Recipe Management <= 1.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Cooked – Recipe Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cooked-timer' shortcode in all versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker...

CVSS:
6.4
Affected:
up to 1.8.0
Fixed in:
1.8.1
Disclosed:
Aug 4, 2024

CVE-2024-41816 on NVD →

Cooked &#8211; Recipe Management [cooked] < 1.8.0 (closed)

unknown

<p>WordPress Cooked Plugin <= 1.7.15.4 is vulnerable to Cross Site Request Forgery (CSRF)</p><p>Software: Cooked</p><p>Link: https://wordpress.org/plugins/cooked/#developers</p><p>Affected Version <= 1.7.15.4</p><p>Fixed in version 1.8.0 </p>

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Jul 18, 2024

Cooked &#8211; Recipe Management [cooked] < 1.8.0 (closed)

unknown

<p>WordPress Cooked Plugin <= 1.7.15.4 is vulnerable to Content Injection</p><p>Software: Cooked</p><p>Link: https://wordpress.org/plugins/cooked/#developers</p><p>Affected Version <= 1.7.15.4</p><p>Fixed in version 1.8.0 </p>

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Jul 18, 2024

Cooked – Recipe Management <= 1.7.15.4 - Cross-Site Request Forgery to Template Apply

medium

The Cooked – Recipe Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.15.4. This is due to missing or incorrect nonce validation on the cooked_save_default_bulk action. This makes it possible for unauthenticated attackers to apply templates in bulk via...

CVSS:
5.4
Affected:
up to 1.7.15.4
Fixed in:
1.8.0
Disclosed:
Jul 17, 2024

CVE-2024-39681 on NVD →

Cooked – Recipe Management <= 1.7.15.4 - Authenticated (Contributor+) HTML Injection

medium

The Cooked – Recipe Management plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.7.15.4. This is due to the plugin not properly escaping/validating input to _recipe_settings. This makes it possible for authenticated attackers, with contributor-level access and above, to inject...

CVSS:
5
Affected:
up to 1.7.15.4
Fixed in:
1.8.0
Disclosed:
Jul 17, 2024

CVE-2024-39682 on NVD →

Cooked – Recipe Management <= 1.7.15.4 - Cross-Site Request Forgery to Template Reset

medium

The Cooked – Recipe Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.15.4. This is due to missing or incorrect nonce validation on the cooked_load_default AJAX action. This makes it possible for unauthenticated attackers to reset templates via a forge...

CVSS:
4.3
Affected:
up to 1.7.15.4
Fixed in:
1.8.0
Disclosed:
Jul 17, 2024

CVE-2024-39679 on NVD →

Cooked – Recipe Management <= 1.7.15.4 - Cross-Site Request Forgery via cooked_get_recipe_ids

medium

The Cooked – Recipe Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.15.4. This is due to missing or incorrect nonce validation on the cooked_get_recipe_ids AJAX action. This makes it possible for unauthenticated attackers to trigger a recipe get requ...

CVSS:
4.3
Affected:
up to 1.7.15.4
Fixed in:
1.8.0
Disclosed:
Jul 17, 2024

CVE-2024-39678 on NVD →

Cooked – Recipe Management <= 1.7.15.4 - Cross-Site Request Forgery to Settings Update

medium

The Cooked – Recipe Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.15.4. This is due to missing or incorrect nonce validation on the cooked_save_default AJAX action. This makes it possible for unauthenticated attackers to update the default_content...

CVSS:
4.3
Affected:
up to 1.7.15.4
Fixed in:
1.8.0
Disclosed:
Jul 17, 2024

CVE-2024-39680 on NVD →

Cooked &#8211; Recipe Management [cooked] < 1.8.0 (closed)

unknown

[en] Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing a...

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Jul 17, 2024

CVE-2024-39680 on NVD →

Cooked &#8211; Recipe Management [cooked] < 1.8.0 (closed)

unknown

[en] Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing a...

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Jul 17, 2024

CVE-2024-39679 on NVD →

Cooked &#8211; Recipe Management [cooked] < 1.8.0 (closed)

unknown

[en] Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing an action they...

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Jul 17, 2024

CVE-2024-39678 on NVD →

Cooked &#8211; Recipe Management [cooked] < 1.8.0 (closed)

unknown

[en] Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitra...

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Jul 17, 2024

CVE-2024-39682 on NVD →

Cooked &#8211; Recipe Management [cooked] < 1.8.0 (closed)

unknown

[en] Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing a...

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Jul 17, 2024

CVE-2024-39681 on NVD →

Cooked – Recipe Management <= Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Cooked – Recipe Management recipe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_recipe_settings[post_title]` parameter in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contribut...

CVSS:
6.4
Affected:
up to 1.7.15.4
Fixed in:
1.8.0
Disclosed:
Jun 13, 2024

CVE-2024-37308 on NVD →

Cooked &#8211; Recipe Management [cooked] < 1.7.15.1 (closed)

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Boxy Studio Cooked plugin <= 1.7.13 versions.

Affected:
up to 1.7.15.1
Fixed in:
1.7.15.1
Disclosed:
Oct 2, 2023

CVE-2023-44477 on NVD →

Cooked <= 1.7.14 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Cooked plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrar...

CVSS:
6.4
Affected:
up to 1.7.14
Fixed in:
1.7.15.1
Disclosed:
Sep 29, 2023

CVE-2023-44477 on NVD →

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 1.1.12
Fixed in:
1.1.13
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

Cooked <= 1.7.9 - Reflected Cross-Site Scripting

medium

The Cooked plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...

CVSS:
6.1
Affected:
up to 1.7.9
Fixed in:
1.7.9.1
Disclosed:
Jun 21, 2021

Cooked &#8211; Recipe Management [cooked] < 1.7.9.1 (closed)

unknown

The Cooked plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...

Affected:
up to 1.7.9.1
Fixed in:
1.7.9.1
Disclosed:
Jun 21, 2021

Cooked &#8211; Recipe Management [cooked] < 1.7.5.6 (closed)

unknown

[en] The Cooked Pro WordPress plugin before 1.7.5.6 was affected by unauthenticated reflected Cross-Site Scripting issues, due to improper sanitisation of user input while being output back in pages as an arbitrary attribute.

Affected:
up to 1.7.5.6
Fixed in:
1.7.5.6
Disclosed:
Apr 22, 2021

CVE-2021-24233 on NVD →

Cooked &#8211; Recipe Management [cooked] < 1.1.13 (closed)

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.1.13
Fixed in:
1.1.13

CVE-2023-33999 on NVD →

Cooked &#8211; Recipe Management [cooked] < 1.7.9.1 (closed)

unknown

The plugin was vulnerable to Unauthenticated Reflected Cross-Site Scripting (XSS). For clarification, this vulnerability is separate to the similar vulnerability CVE-2021-24233.

Affected:
up to 1.7.9.1
Fixed in:
1.7.9.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database