Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-06-17

CVE-2026-3011 - Recipe Card Blocks Lite Plugin

The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions up to, and including, 3.4.13. This is due to the 'WPZOOM_Helpers::deserialize_block_attributes' method converting unicode-encoded sequences back into HTML characters after sanitization has already been applied. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that execute whenever a user accesses the published post or the print view of an injected recipe.

PLUGIN Recipe Card Blocks Lite

CVE-2026-3011

MEDIUM CVSS 6.4 2026-06-08
Threat Entry Updated 2026-01-26

CVE-2025-14973 - Recipe Card Blocks Lite Plugin

The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a SQL statement, allowing contributors and above to perform SQL injection attacks.

PLUGIN Recipe Card Blocks Lite

CVE-2025-14973

MEDIUM CVSS 6.8 2026-01-26
Scroll to top