Cooked – Recipe Management <= 1.16.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via [cooked-timer] Shortcode

Medium 6.4 CWE-79Fixed in 1.16.2
ID
WPSEC-2026-0509
Plugin
Cooked – Recipe Management (cooked)
Affected
from 1.8.1 before 1.16.2
Remediation
Update to 1.16.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Cooked – Recipe Management on WPSec AttackSurface
Fix released
Published

Description

The Cooked – Recipe Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [cooked-timer] shortcode (and its [timer] alias) in versions 1.8.1 up to, and including, 1.16.1 due to insufficient output escaping of the timer description in the data-desc attribute. When no 'desc' attribute is given, the description is taken from the shortcode's enclosed content, which is only passed through wp_strip_all_tags(); that function does not encode quotes, so the value can break out of the attribute. This makes it possible for authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0