{"id":"CVE-2024-41816","summary":"WordPress Cooked Plugin Persistent Cross-Site Scripting via Shortcode","details":"Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the ‘[cooked-timer]’ shortcode in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with subscriber-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a compromised page. This issue has been addressed in release version 1.8.1. All users are advised to upgrade. There are no known workarounds for this vulnerability.","aliases":["GHSA-3gw3-2qjq-xqjj"],"modified":"2026-08-12T03:51:25.094460346Z","published":"2024-08-05T20:12:41.428Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/41xxx/CVE-2024-41816.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/41xxx/CVE-2024-41816.json"},{"type":"ADVISORY","url":"https://github.com/XjSv/Cooked/security/advisories/GHSA-3gw3-2qjq-xqjj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-41816"},{"type":"FIX","url":"https://github.com/XjSv/Cooked/commit/ac7455bdccc99fb2f5b3c7611312947c1623c3ec"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/xjsv/cooked","events":[{"introduced":"0"},{"fixed":"fb2c0657286eed7b0c3a2f12859827c8afcfab38"},{"fixed":"ac7455bdccc99fb2f5b3c7611312947c1623c3ec"}],"database_specific":{"cpe":"cpe:2.3:a:boxystudio:cooked:*:*:*:*:pro:wordpress:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.8.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.8.0","v1.7.15.4","v1.7.15.3","v1.7.15.2","v1.7.14"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-41816.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}