ExploitMatch
Back

CVE-2026-86602

Monitor on ThreatCluster

Description

The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes.