PT-2026-69374 · WordPress · Checkview

·

CVE-2026-18786

·

Published

2026-08-10

·

Updated

2026-08-11

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CheckView versions prior to 2.3.2
Description The plugin fails to restrict its REST API authentication filter to its own routes. It unconditionally discards authentication errors for any request where the URI contains a specific string related to the plugin. This allows unauthenticated attackers to bypass the REST nonce check—a security token used to prevent Cross-Site Request Forgery (CSRF)—and execute any REST action available to a logged-in administrator, including the creation of a new administrator account, by tricking an administrator into clicking a crafted link.
Recommendations Update CheckView to version 2.3.2 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18786

Affected Products

Checkview