External risk intelligence

WP Recipe Maker Arbitrary Shortcode Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-89274

The vulnerability affects a WordPress plugin designed for public-facing recipe pages. It is triggered during the standard rendering of these public pages when a user views a recipe, making the vulnerable surface an internet-accessible web endpoint by design.

Code Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in the WP Recipe Maker WordPress plugin. The issue allows for the execution of unauthorized commands within the website's infrastructure when specific content is displayed, potentially leading to the disclosure of sensitive information embedded in recipe metadata. The primary concern at this stage is to confirm if this plugin is in use and assess the exposure risk.

  • Plugin allows unauthorized code execution on websites.
  • Critical vulnerability impacts data displayed on public pages.
  • Confirm plugin use and assess any potential data exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can submit a comment with malicious shortcodes to a recipe that a site moderator eventually approves. When any visitor views the recipe page, the plugin executes these shortcodes server-side, potentially exposing sensitive information through the recipe's metadata.

  • Requires an approved comment.
  • Shortcodes executed during page render.
  • Risk of sensitive data exposure.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to execute arbitrary WordPress shortcodes on recipe pages when those pages are rendered. If an attacker's comment is approved, they could inject shortcodes that embed sensitive information or alter displayed content into the recipe's structured data, making it visible to anyone viewing the recipe.

  • Recipe page data and linked content.
  • Via approved user comments and page rendering.
  • Public disclosure of sensitive content.

Operational Fix

Recommended remediation, mitigation, and detection steps

The WP Recipe Maker plugin's shortcode execution vulnerability requires action from teams managing WordPress applications. First, identify all WordPress sites utilizing this plugin, then confirm which instances are internet-facing and host business-critical content. Next, locate the accountable application owner or administrator. Finally, plan remediation by coordinating with the plugin vendor or implementing a temporary risk reduction strategy if immediate patching is not feasible.

  • Application owners should prioritize this issue.
  • Verify internet-facing plugin instances first.
  • Coordinate vendor updates and plan maintenance.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the WP Recipe Maker plugin?

WP Recipe Maker is a WordPress plugin that helps site owners create, manage, and display structured recipe content. It automatically formats ingredients, instructions, and metadata so search engines can better index the culinary data. This software is commonly used by food bloggers and recipe sites to enhance the visual presentation and search engine visibility of their content.

What does CVE-2026-89274 mean?

This vulnerability is classified as Improper Control of Generation of Code, or CWE-94. It means the plugin inadvertently treats user-submitted content as actionable code. Specifically, the software attempts to clean recipe metadata but mistakenly runs shortcodes before checking them. This allows an attacker to force the server to process WordPress shortcodes, which can output data that should remain hidden.

How is this vulnerability triggered?

An attacker must submit a comment containing a malicious shortcode to a recipe page. The vulnerability is only triggered if that comment is approved by a moderator or through an auto-approval setting. If the comment remains pending or is rejected, the shortcode will not execute. Once approved, the code runs automatically whenever a user views the recipe page.

Is my site at risk from this issue?

If you host WordPress recipe pages that allow user comments, your site is likely affected. According to Halo Surface Signal, this software component is designed to be internet-facing, meaning the vulnerable code is exposed to public web traffic by design. You should consider any installation that renders recipe pages to be part of the reachable attack surface.

What should I do to secure my site?

First, inventory your WordPress sites to identify which instances are running the WP Recipe Maker plugin. Coordinate with your application administrators to verify if your site allows recipe comments. If you cannot update the plugin to a secured version immediately, consider disabling comment functionality on recipe pages as a temporary measure to block the execution path.

References