Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 27 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brechtvds
Brechtvds wp Recipe Maker Wordpress Wordpress wordpress |
|
| Vendors & Products |
Brechtvds
Brechtvds wp Recipe Maker Wordpress Wordpress wordpress |
|
| Metrics |
ssvc
|
Fri, 27 Feb 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, and including, 10.3.2. This is due to the /wp-json/wp-recipe-maker/v1/integrations/instacart REST API endpoint's permission_callback being set to __return_true and a lack of subsequent authorization or ownership checks on the user-supplied recipeId. This makes it possible for unauthenticated attackers to overwrite arbitrary post metadata (wprm_instacart_combinations) for any post ID on the site via the recipeId parameter. | |
| Title | WP Recipe Maker <= 10.3.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Metadata Modification via 'recipeId' Parameter | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:06:48.448Z
Reserved: 2026-01-28T18:19:24.671Z
Link: CVE-2026-1558
Updated: 2026-02-27T15:44:45.627Z
Status : Deferred
Published: 2026-02-27T05:18:19.950
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-1558
No data.
OpenCVE Enrichment
Updated: 2026-04-15T20:15:13Z