Medium severity6.5NVD Advisory· Published Sep 23, 2026
CVE-2026-86601
CVE-2026-86601
Description
The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing unauthenticated users to have arbitrary shortcodes executed server side and to read the content of unpublished recipes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <10.8.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.