Wpdelicious operates a WordPress plugin that recurs with vulnerabilities centered on input-handling and file-system control issues, including cross-site scripting flaws and improper file-path validation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpdelicious over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7626HIGH The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file movement and reading due to insufficient file p | Sep 11, 2024 | 8.1 | 23 | NO | NO |
CVE-2025-67548MEDIUM Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Del | Dec 9, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-58605MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious delicious-recipes allows Stored XSS.This issue affec | Sep 3, 2025 | 6.5 | 21 | NO | NO |
CVE-2026-39528MEDIUM Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Del | Apr 8, 2026 | 5.3 | 19 | NO | NO |
CVE-2025-54023MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious delicious-recipes allows DOM-Based XSS.This issue af | Jul 16, 2025 | 6.5 | 18 | NO | NO |
CVE-2024-43935MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Delicious Delicious Recipes – WordPress Recipe Plugin allows Stored | Aug 29, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpdelicious.
Media articles that mention a CVE ID that affects a product developed by Wpdelicious — matched by CVE ID, not by vendor name.