CVE-2024-39682 is an HTML Injection vulnerability affecting the Cooked recipe plugin for WordPress, versions up to and including 1.7.15.4. This medium-severity vulnerability (CVSS 5.4) allows authenticated attackers with contributor-level access to inject arbitrary HTML, potentially leading to client-side content manipulation. While there are no known exploits in the wild, no public exploit code, and minimal community discussion, users are strongly advised to upgrade to Cooked version 1.8.0 to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.0CPE matchmatch criteria | cpe:2.3:a:boxystudio:cooked:*:*:*:*:pro:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.