CVE-2026-75905
Deferred Deferred - Pending Action

Authorization Bypass in WP Recipe Maker Plugin

Vulnerability report for CVE-2026-75905, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: Wordfence

Description

The WP Recipe Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to take ownership of any admin-authored recipe by rewriting its post_author to the attacker's user ID, and unpublish it by overwriting its post_status with the contributor's draft or pending post status. This requires the default 'recipe_use_author' setting to be set to 'parent' for the ownership transfer to occur, though unpublishing remains possible regardless of this setting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_recipe_maker wp_recipe_maker to 10.8.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WP Recipe Maker plugin for WordPress has an authorization bypass flaw in versions up to 10.8.0. It fails to verify user permissions properly, allowing authenticated attackers with contributor-level access or higher to take ownership of admin-authored recipes by changing the post author to their user ID. They can also unpublish recipes by altering the post status to draft or pending.

Detection Guidance

To detect this vulnerability, check WordPress sites running WP Recipe Maker versions up to 10.8.0. Look for unauthorized changes to recipe ownership or post status. Review user roles with contributor access or higher for suspicious activity. Inspect database entries for post_author modifications or post_status changes to draft/pending.

Impact Analysis

If exploited, this vulnerability could allow attackers to modify or remove recipes created by administrators without authorization. This could disrupt content integrity, misrepresent ownership, or cause loss of published recipes, affecting the functionality and credibility of the WordPress site.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by allowing unauthorized users to modify or unpublish admin-authored recipes. Unauthorized changes to data may violate integrity requirements under these regulations, particularly if recipes contain sensitive or personal information. However, the provided CVE details do not explicitly link this issue to compliance violations.

Mitigation Strategies

Update the WP Recipe Maker plugin to the latest version beyond 10.8.0 immediately. Disable the plugin temporarily if an update is not available. Review user roles and permissions to ensure contributors and above do not have unnecessary access. Monitor for unauthorized changes to recipes or admin accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75905. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart