Cooked – Recipe Management <= 1.16.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via [cooked-timer] Shortcode
- ID
- WPSEC-2026-0509
- Plugin
- Cooked – Recipe Management (cooked)
- Affected
- from 1.8.1 before 1.16.2
- Remediation
- Update to 1.16.2 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- Cooked – Recipe Management on WPSec AttackSurface
- Fix released
- Published
Description
The Cooked – Recipe Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [cooked-timer] shortcode (and its [timer] alias) in versions 1.8.1 up to, and including, 1.16.1 due to insufficient output escaping of the timer description in the data-desc attribute. When no 'desc' attribute is given, the description is taken from the shortcode's enclosed content, which is only passed through wp_strip_all_tags(); that function does not encode quotes, so the value can break out of the attribute. This makes it possible for authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
References
- https://wpsec.com/vuln/WPSEC-2026-0509/
- https://plugins.svn.wordpress.org/cooked/tags/1.16.2/
- https://wordpress.org/plugins/cooked/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS