📦 Cooked

by Boxystudio

🔍 What is Cooked?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-49290

MEDIUM CVSS 4.3 Oct 20, 2024

This CSRF vulnerability in the Cooked Pro WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions. It affects WordPress sites using Cooked Pro versio...

CVE-2024-41816

MEDIUM CVSS 5.4 Aug 5, 2024

This vulnerability allows authenticated WordPress users with subscriber-level access or higher to inject malicious scripts via the '[cooked-timer]' shortcode. The scripts persist in pages and execute ...

CVE-2024-39679

MEDIUM CVSS 4.3 Jul 18, 2024

The Cooked WordPress plugin up to version 1.7.15.4 has a CSRF vulnerability in its AJAX action handler due to missing nonce validation. This allows attackers to trick authenticated WordPress users int...

CVE-2024-39681

MEDIUM CVSS 5.4 Jul 18, 2024

The Cooked WordPress plugin up to version 1.7.15.4 has a CSRF vulnerability in its AJAX action handler due to missing nonce validation. This allows attackers to trick authenticated WordPress users int...

CVE-2024-37308

MEDIUM CVSS 5.4 Jun 13, 2024

The Cooked Pro WordPress recipe plugin has a stored XSS vulnerability that allows authenticated attackers with contributor-level access or higher to inject malicious scripts into recipe pages. These s...