Insecure Direct Object Reference in WP Recipe Maker Plugin by WordPress
CVE-2026-1558
What is CVE-2026-1558?
The WP Recipe Maker plugin for WordPress contains a vulnerability that allows unauthenticated users to exploit the /wp-json/wp-recipe-maker/v1/integrations/instacart REST API endpoint. The permission_callback for this endpoint is incorrectly set to __return_true, thereby bypassing necessary authorization checks. This oversight enables attackers to manipulate the recipeId parameter to overwrite arbitrary post metadata (specifically wprm_instacart_combinations) for any post ID present on the site, leading to potential data integrity issues.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Recipe Maker * <= 10.3.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved