PT-2026-69266 · WordPress · Create
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Create WordPress plugin versions prior to 2.5.4
Description
An authorization check is missing before returning content over a REST API route. As a side effect, this route publishes the requested content, which allows unauthenticated attackers to read unpublished content and make it publicly available.
Recommendations
Update the Create WordPress plugin to version 2.5.4 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Create