CVE-2026-86608
📛 CVE Title
WP Recipe Maker 9.8.0 - 10.8.1 - Unauthenticated DoS via Unbounded User Meta Insertion
Description
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what that route stores, allowing unauthenticated users to write unlimited data into any user's metadata and to permanently prevent that account, including an administrator's, from loading.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- WPScan
- CVSS severity
- —
- CVSS score
- —
- CVSS vector
- —
- Effective score
- 8.2 / 10 HIGH source: NVD
- CWE(s)
-
CWE-400 Uncontrolled Resource Consumption - Reserved
- 2026-09-08
- Published
- 2026-09-23 06:00 UTC
- Last updated
- 2026-09-23 10:55 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/86xxx/CVE-2026-86608.json
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-23 06:17:04 UTC
- NVD last modified
- 2026-09-23 18:13:31 UTC
- NVD CVSS v3.1
- 8.2 / 10 HIGH source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 4.2 / 10
- EPSS score
- 0.0020 (probability of exploitation in next 30 days)
- EPSS percentile
- 9.97% vs all CVEs — higher = more likely to be exploited, as of 2026-09-23
NVD-assigned CWE(s):
CWE-400
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-09-24 04:33 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-85044 - Assigner
- WPScan
- Published
- Sep 23, 2026, 6:00:19 AM
- Updated
- Sep 23, 2026, 10:55:24 AM
- EUVD base score (CVSS 3.1)
-
8.2 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H - EUVD-reported EPSS
- 0.2000
- Vendors
- Unknown
- Products
-
WP Recipe Maker (9.8.0 <10.8.2)
- Aliases
-
GHSA-qqpr-953f-6p7v
ENISA description: The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what that route stores, allowing unauthenticated users to write unlimited data into any user's metadata and to permanently prevent that account, including an administrator's, from loading.
EUVD references (1)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Unknown | WP Recipe Maker |
9.8.0 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- https://wpscan.com/vulnerability/d7f0f9dd-4180-4210-9c48-dae67e8f5d8e/ exploitvdb-entrytechnical-description
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (1)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://wpscan.com/vulnerability/d7f0f9dd-4180-4210-9c48-dae67e8f5d8e/ contact@wpscan.com
Remediations (10)
-
web:0patch.com
Tiny reboot-less security patches for critical vulnerabilities in Windows, Microsoft Office, and other Windows products
2026-09-24 11:49 UTC -
web:epatch.pa.gov
Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...
2026-09-24 11:49 UTC -
web:hypixel.net
All SkyBlock Patch Notes can be found here! You can click the Watch button in this section to be alerted when new Patch Notes are released!
2026-09-24 11:49 UTC -
web:playvalorant.com
GENERAL UPDATES With Patch 13.06, VALORANT Console is now available in Australia and New Zealand! G'day and kia ora, gamers! KNOWN ISSUES Competitive Console issue for mode selection when in Range in Queue Modes When exiting the queue, you may be unable to enter the Range for a moment even while not in any queue. This will be fixed in a ...
2026-09-24 11:49 UTC -
web:support.microsoft.com
Want a quick overview?: Watch the Windows 11 release note video for this update.
2026-09-24 11:49 UTC -
web:windowsreport.com
Microsoft's September 2026 Patch Tuesday fixes a record 966 security vulnerabilities, including two zero-days that attackers are actively exploiting. Microsoft has released Patch Tuesday updates for Windows 11 alongside Windows 10 KB5122878, delivering what appears to be the company's largest ...
2026-09-24 11:49 UTC -
web:www.it-connect.tech
Fix the September 2026 RDS bug on Windows Server with Microsoft's KIR rollback. Learn deployment steps and keep the security update installed.
2026-09-24 11:49 UTC -
web:www.linkedin.com
Microsoft has released its largest Patch Tuesday security update to date, addressing over 900 vulnerabilities across Windows and other products, including two privilege-escalation flaws that ...
2026-09-24 11:49 UTC -
web:www.oracle.com
Oracle Critical Security Patch Update Advisory - August 2026 Description. A Critical Security Patch Update (CSPU) provides targeted, high-priority security fixes in a smaller, mor
2026-09-24 11:49 UTC -
web:www.stalker2.com
Patch notes A comprehensive archive of changes, tweaks, and fixes introduced with every patch and major update of S.T.A.L.K.E.R. 2: Heart of Chornobyl. Your feedback helps us refine the Zone — if you encounter an anomaly that doesn't belong there, report it via the Technical Support Hub.
2026-09-24 11:49 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-86608.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-86608",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T10:41:21.072442Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400 Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T10:55:24.252Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "WP Recipe Maker",
"vendor": "Unknown",
"versions": [
{
"lessThan": "10.8.2",
"status": "affected",
"version": "9.8.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Isuka sanuj"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what that route stores, allowing unauthenticated users to write unlimited data into any user's metadata and to permanently prevent that account, including an administrator's, from loading."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-400 Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T06:00:19.084Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/d7f0f9dd-4180-4210-9c48-dae67e8f5d8e/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "WP Recipe Maker 9.8.0 - 10.8.1 - Unauthenticated DoS via Unbounded User Meta Insertion",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-86608",
"datePublished": "2026-09-23T06:00:19.084Z",
"dateReserved": "2026-09-08T08:46:31.818Z",
"dateUpdated": "2026-09-23T10:55:24.252Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}