๐Ÿ” CVE Alert

CVE-2026-16992

UNKNOWN 0.0

Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publication

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.

Vendor unknown
Product create
Published Aug 9, 2026
Stay Ahead of the Next One

Get instant alerts for unknown create

Be the first to know when new unknown vulnerabilities affecting unknown create are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Create
0 < 2.5.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/d85653f7-8556-4bac-8860-fbacc63ba5df/

Credits

Pedro Pinho WPScan