CVE-2026-1558 | WP Recipe Maker Plugin up to 10.3.2 on WordPress REST API Endpoint instacart permission_callback recipeId resource injection
A vulnerability labeled as critical has been found in WP Recipe Maker Plugin up to 10.3.2 on WordPress. Affected by this issue is the function permission_callback of the file /wp-json/wp-recipe-maker/v1/integrations/instacart of the component REST API Endpoint. Such manipulation of the argument recipeId leads to improper control of resource identifiers.
This vulnerability is listed as CVE-2026-1558. The attack may be performed from remote. There is no available exploit.