CVE-2026-86603
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 23, 2026
Vendor
unknown
Description
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.