Authorization Bypass Vulnerability in WP Recipe Maker Plugin by WordPress
CVE-2026-75905

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 September 2026

What is CVE-2026-75905?

The WP Recipe Maker plugin for WordPress contains a significant vulnerability that allows authenticated users with contributor-level access or higher to exploit authorization bypass. This flaw enables attackers to take control of recipes authored by admin users by changing the ownership of the recipe to their user ID. This can be accomplished by modifying the post_author field and can also lead to unpublishing admin-created content by altering its post_status to either draft or pending, dependent on the default 'recipe_use_author' setting. The risk is present in all versions leading up to and including 10.8.0.

Affected Version(s)

WP Recipe Maker 0 <= 10.8.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.