{"api_version":"v1","generated_at":"2026-10-08T19:55:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-gora-tech-cooked-f26bdde3b37b","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/cooked","name":"Cooked","next_cursor":null,"observations":[{"affected":"Cooked: n/a \u2264 1.16.0","affected_versions_present":true,"cve_id":"CVE-2026-73999","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73999","fixed":"Update the WordPress Cooked Plugin to the latest available version (at least 1.16.1).","last_modified":"2026-09-19T14:21:53.749Z","patch_url":"https://patchstack.com/database/wordpress/plugin/cooked/vulnerability/wordpress-cooked-plugin-1-16-0-insecure-direct-object-references-idor-vulnerability?_s_id=cve","primary_source":"","published":"2026-09-17T13:24:52.301Z"},{"affected":"Cooked: \u2264 1.11.3","affected_versions_present":true,"cve_id":"CVE-2025-62989","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-62989","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T16:14:07.767Z","patch_url":"","primary_source":"","published":"2025-12-31T17:19:24.282Z"},{"affected":"Cooked: \u2264 1.11.3","affected_versions_present":true,"cve_id":"CVE-2025-68586","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68586","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T16:14:30.893Z","patch_url":"","primary_source":"","published":"2025-12-24T13:10:42.037Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"Gora Tech"}}
