Authorization Bypass in Create WordPress Plugin
CVE-2026-16992
Key Information:
Badges
What is CVE-2026-16992?
The Create WordPress plugin versions prior to 2.5.4 contain a significant vulnerability where an authorization check is not enforced on certain REST API routes. This oversight allows attackers to access unpublished content without authentication, potentially leading to unauthorized exposure of sensitive information. Furthermore, this flaw enables attackers to publish the content they access, worsening the situation by making it publicly available without the consent of the author. It is crucial for operators using this plugin to update to the latest version to mitigate the risk of such unauthorized access.
Affected Version(s)
Create 0 < 2.5.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.