Insecure Direct Object Reference in WP Recipe Maker Plugin by WordPress
CVE-2026-1558
5.3MEDIUM
What is CVE-2026-1558?
The WP Recipe Maker plugin for WordPress contains a vulnerability that allows unauthenticated users to exploit the /wp-json/wp-recipe-maker/v1/integrations/instacart REST API endpoint. The permission_callback for this endpoint is incorrectly set to __return_true, thereby bypassing necessary authorization checks. This oversight enables attackers to manipulate the recipeId parameter to overwrite arbitrary post metadata (specifically wprm_instacart_combinations) for any post ID present on the site, leading to potential data integrity issues.
Affected Version(s)
WP Recipe Maker 0 <= 10.3.2