Critical WordPress plugin vulnerability allows arbitrary code execution

WP Recipe Maker version 10.8.1 and earlier contains CVE-2026-89274, a critical code-injection flaw allowing unauthenticated attackers to execute arbitrary shortcodes via unsanitized comment ratings. The vulnerability was disclosed on 2026-09-19 with a near-perfect severity rating.

2 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Wordfence has several new advisories, a couple of which are close to a perfect 10. CRITICAL: WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content https:

mastodon:infosec-exchangeother11d ago kagi ↗

Wordfence has several new advisories, a couple of which are close to a perfect 10. CRITICAL: WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content https://www. wordfence.com/threat-intel/vul nerabilities/wordpress-plugins/wp-recipe-maker/wp-recipe-maker-1081-unauthenticated-arbitrary-shortcode-execution-via-recipe-comment-content CRITICAL: Gravity For

WP Recipe Maker <=10.8.1 hit by CVE-2026-89274: CRITICAL code injection via unsanitized shortcodes in comment ratings. Unauthenticated attackers can trigger arbitrary shortcode execution on recipe pag

mastodon:infosec-exchangeother10d ago kagi ↗

WP Recipe Maker <=10.8.1 hit by CVE-2026-89274: CRITICAL code injection via unsanitized shortcodes in comment ratings. Unauthenticated attackers can trigger arbitrary shortcode execution on recipe pages. Upgrade ASAP. https:// radar.offseq.com/threat/cve-20 26-89274-cwe-94-improper-control-of-generation-of-code-code-injection-in-brechtvds-wp-recipe-77a2426acb987f3a # OffSeq # WordPress # CVE202689