CVE-2026-16992
Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publication
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.
| Vendor | unknown |
| Product | create |
| Published | Aug 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown create
Be the first to know when new unknown vulnerabilities affecting unknown create are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Create
0 < 2.5.4
References
Credits
Pedro Pinho WPScan