Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes. | |
| Title | WP Recipe Maker 10.3.0 - 10.8.1 - Subscriber+ Draft and Private Recipe Content Disclosure via wprm_shortcode_preview | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T10:55:53.223Z
Reserved: 2026-09-08T08:38:31.554Z
Link: CVE-2026-86602
Updated: 2026-09-23T10:35:41.278Z
Status : Received
Published: 2026-09-23T06:17:03.820
Modified: 2026-09-23T11:17:14.103
Link: CVE-2026-86602
No data.
OpenCVE Enrichment
Updated: 2026-09-23T15:30:07Z