Delicious Recipes <= 1.9.0 - Authenticated (Contributor+) Arbitrary File Upload
Vulnerability Description
The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file uploads when importing recipes via CSV in all versions up to, and including, 1.9.0. This flaw allows an attacker with at least Contributor-level permissions to upload a malicious PHP file by providing a remote URL during a recipe import process, leading to Remote Code Execution (RCE).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11755
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Matthew Rollings
- Youcef Hamdani
References
Affected Vendor
wpdelicious
View all reports →