WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) < 1.10.2 - Missing Authorization
medium
The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 1.10.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.10.2
- Fixed in:
- 1.10.2
- Disclosed:
- Jul 30, 2026
CVE-2026-14305 on NVD →
WP Delicious <= 1.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'steps' Block Attribute
medium
The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and including, 1.10.2. This is due to insufficient input sanitization and output escaping in the wrap_direction_text() function, which interpolates the user-supplied href value from...
- CVSS:
- 6.4
- Affected:
- up to 1.10.2
- Fixed in:
- 1.10.3
- Disclosed:
- Jul 15, 2026
CVE-2026-15099 on NVD →
Delicious <= 1.9.5 - Missing Authorization
medium
The Delicious plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.9.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.6
- Disclosed:
- Feb 25, 2026
CVE-2026-39528 on NVD →
WP Delicious <= 1.9.1 - Missing Authorization
medium
The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.9.1. This makes it possible for authenticated attackers, with Contributor-level access and abo...
- CVSS:
- 4.3
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.2
- Disclosed:
- Nov 9, 2025
CVE-2025-67548 on NVD →
Delicious Recipes <= 1.9.0 - Authenticated (Contributor+) Arbitrary File Upload
high
The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file uploads when importing recipes via CSV in all versions up to, and including, 1.9.0. This flaw allows an attacker with at least Contributor-level permissions to upload a malicious PHP file...
- CVSS:
- 8.8
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.1
- Disclosed:
- Oct 31, 2025
CVE-2025-11755 on NVD →
WP Delicious <= 1.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP Delicious plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.4
- Affected:
- up to 1.8.7
- Fixed in:
- 1.8.8
- Disclosed:
- Sep 3, 2025
CVE-2025-58605 on NVD →
WP Delicious <= 1.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP Delicious plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.4
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.5
- Disclosed:
- Jul 16, 2025
CVE-2025-54023 on NVD →
WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) <= 1.6.9 - Improper Path Validation to Authenticated (Subscriber+) Arbitrary File Move and Read
high
The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file movement and reading due to insufficient file path validation in the save_edit_profile_details() function in all versions up to, and including, 1.6.9. This makes it possible for authentic...
- CVSS:
- 8.1
- Affected:
- up to 1.6.9
- Fixed in:
- 1.7.0
- Disclosed:
- Sep 10, 2024
CVE-2024-7626 on NVD →
Delicious Recipes – WordPress Recipe Plugin <= 1.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Delicious Recipes – WordPress Recipe Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arb...
- CVSS:
- 6.4
- Affected:
- up to 1.6.7
- Fixed in:
- 1.6.8
- Disclosed:
- Aug 26, 2024
CVE-2024-43935 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.3
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Freemius SDK <= 2.4.2 - Missing Authorization Checks
medium
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- CVSS:
- 6.3
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5
- Disclosed:
- Mar 4, 2022
CVE-2022-4974 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database