Pricing
Case studies
Login
Start trial
WP Recipe Maker
Brecht
Developer
10.4.0
Latest version
50,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
20 patched
3 Mitigation rules
Insecure Direct Object Reference to Unauthenticated Arbitrary Post Metadata Modification via 'recipeId' Parameter vulnerability
<= 10.3.2
26/02/2026
Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure vulnerability
<= 10.2.3
24/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via 'group_tag' vulnerability
<= 9.1.0
03/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' vulnerability
<= 9.1.0
03/02/2026
Broken Access Control vulnerability
<= 10.2.4
28/01/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 10.2.3
16/12/2025
Insecure Direct Object Reference to Sensitive Information Exposure vulnerability
<= 10.2.2
12/12/2025
Content Injection vulnerability
< 10.1.0
26/09/2025
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 9.8.0
12/03/2025
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'tooltip' vulnerability
<= 9.6.1
24/10/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via wprm-recipe-roundup-item Shortcode vulnerability
<= 9.3.1
02/05/2024
Authenticated Stored Cross-Site Scripting via Video Embed vulnerability
<= 9.2.1
14/03/2024
Missing Authorization to Authenticated (Subscriber+) SQL Injecton vulnerability
<= 9.1.2
08/02/2024
Directory Traversal vulnerability
<= 9.1.0
18/01/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 9.1.0
18/01/2024
Reflected Cross-Site Scripting via Referer vulnerability
<= 9.1.0
18/01/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Recipe Notes vulnerability
<= 9.1.0
18/01/2024
Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 9.1.0
18/01/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via header_tag vulnerability
<= 9.1.0
18/01/2024
Contributor+ Stored XSS vulnerability
< 8.6.1
20/12/2022